Greetings,
I would like to request the assistance of this wonderful discussion group as we are completing the final
phase of testing Firewall-1. The Host configuration is Firewall-1 v2.0, on Sparc 5, SUNOS v5.x with two 16mb
token ring cards. The Intranet consists of remote sites which currently pass through a Crosscomm router
at the remote location to a Crosscomm router at the Host location then onto token ring LAN.
The problem:
Remote PC on Remote Token Ring LAN attempts to access WEB server located at Host LAN and never
receives data. Sniffed the packet and this is what we got:
Source Destination
164.106.remote.pc www.webserver (SYN SEQ=####, TCP D=80)
www.webserver 164.106.remote.pc (SYN ACK=###, TCP D=1635)
www.webserver 164.106.remote.pc (SYN ACK=###, transport retransmission, TCP D=1635)
164.106.remote.pc www.webserver (SYN ACK=###, transport retransmission, TCP D=80)
www.webserver 164.106.remote.pc (SYN SEQ=###, TCP D=1635)
164.106.firewall www.webserver (ACK=####, redirect host ICMP Redirect)
(Redirect datagrams for the host )
www.webserver 164.106.remote.pc (2 routers to local station, TCP D=1635)
www.webserver 164.106.remote.pc (URG ACK, TCP D=1635)
164.106.remote.pc www.webserver (SYN ACK, TCP D=80)
www.webserver 164.106.remote.pc (SYN SEQ=###, TCP D=1635)
164.106.firewall www.webserver (ACK=###, Redirect host ICMP Redirect)
(Redirect datagrams for the host)
www.webserver 164.106.remote.pc (TCP D=1635)
www.webserver 164.106.remote.pc (URG ACK=###, TCP D=1635)
164.106.remote.pc www.webserver (SYN ACK, TCP D=80)
www.webserver 164.106.remote.pc (SYN SEQ=###, TCP D=1635)
164.106.firewall www.webserver (ACK=###, Redirect host ICMP Redirect)
(Redirect datagrams for the host)
repeat above 5 lines, the barf
Additional information:
Data from WEBserver never reaches remote PC and is not visible on the Firewall-1 log viewer. Also, if the
Firewall is stopped, remote pc receives data from WEBserver, yet still redirects 3 times.
Any suggestions would be appreciated.
TIA,
Pam
Internet: SOPERDP @
SO .
CC .
VA .
US
Phone: 804-225-2348
Fax: 804-371-2330
|
|