Great Circle Associates Firewalls
(March 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall with no Internet Connection
From: jim @ wvlink . mpl . com (Jim Poling)
Date: Fri, 8 Mar 1996 08:02:32 -0800 (PST)
To: <wombat @ mcfeely . bsfs . org>, firewalls @ greatcircle . com

>Could you ping through the firewall system before adding the firewall (in 
>other words, was the system housing the firewall routing between 
>interfaces before any rules werre imposed) ?
>
>----------------------------------------
>Rabid Wombat
>wombat @
 mcfeely .
 bsfs .
 org
>----------------------------------------
>

No, the sole purpose of the system housing the firewall, is just the
firewall.  Before the firewall, there was just a direct connection.  Are you
saying that
the packets aren't getting routed? 
>
>
>
>
>On Wed, 6 Mar 1996, Jim Poling wrote:
>
>> I'm trying to get a BorderWare Firewall server to work on my client's VERY
>> large internal network, as a secure was of authenticating dialup PPP users
>> between the terminal server (Only thing on the external side of the FW),
>> and the large internal network.
>> 
>>    I've got the newest demo of the borderware FW server, 
>> and I'm getting the following syptoms.
>> 
>>         -Internal network can ping internal side of Firewall and Vice Versa.
>> 
>>         -External network can ping external side of Firewall and Vice Versa.
>>         -Internal network cannot ping either external side of FW or external
>> network, and Vice Versa.
>> 
>>    In the General Log section, it says
>> 
>> Mar 6, 17:21:40 PWC Kernel kpf rule
#10,ef0,141.192.100.102,0,141.192.100.101,
>> 8,0,1,permit
>> (This is internal terminal server to external FW)
>> 
>> Mar 6, 17:21:47 PWC Kernel kpf rule #14,ef0,141.192.100,102,0,141.119.42.245,
>> 8,1,1,deny
>> (This is external terminal server to internal FW)
>> 
>> At least I know it can't be a cabling problem now.  The FW is actually
denying
>> access to the internal network, and all of the PING's are turned on.  As a
>> matter
>> of fact I went ahead and turned EVERYTHING on to be sure.
>> 
>> Anybody have any clues?
>> 
>> Thanks,
>> -JIM Poling
>>  MPL Corp.
>>  Buckhannon, WV
>>  (304)472-9520
>>  JIM @
 WVLINK .
 MPL .
 COM
>> 


Indexed By Date Previous: subsribe firewalls-digest
From: Paul Gustafson/Shiva Corporation <pgustafson @ shiva . com>
Next: Re: Eternal war: gateway versus filtering
From: Rolf Weber <weber @ iez . com>
Indexed By Thread Previous: Re: Firewall with no Internet Connection
From: jim @ wvlink . mpl . com (Jim Poling)
Next: Product list: Firewalls for Windows NT
From: pmoen @ sbnsw . com . au

Google
 
Search Internet Search www.greatcircle.com