Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: [FW1] Firewall 2.1 , Solaris and rouing
From: Joe Loiacono <jloiacon @ csc . com>
Organization: Computer Sciences Corporation
Date: Wed, 26 Feb 1997 14:57:59 -0500
To: JERALD JOSEPHS <jerald . josephs @ Sun . COM>
Cc: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>, Jerald Josephs <jerald . josephs @ Ebay . Sun . COM>, "Raymond.Sleiman" <Raymond . Sleiman @ mail . gestronic . ch>, daniel <daniel @ elmail . co . uk>, sun-managers <sun-managers @ ra . mcs . anl . gov>, firewalls <firewalls @ GreatCircle . COM>, fw-1-mailinglist <fw-1-mailinglist @ us . checkpoint . com>
References: <199702211325 . FAA08264 @ notesgw2 . sybase . com> <330DEB7A . 769F @ Sun . COM>

JERALD JOSEPHS wrote:

> > You should not run in.routed nor should you run in.rdisc on your
> > firewall gateway.

OK, I'll buy this. My guess is that you shouldn't run routed because it
is susceptable to attack, as well as you don't want to advertise info
(routing info) about your network.

So, I turned them off (reboot with newly included defaultrouter file).
However, now I can't get packets to forward, even though:

1. IP forwarding is on (=1, I've even set it to 2 since I have a DMZ)
2. Routing table (netstat -rvn) still has all route/gateway pairs
including default
3. /etc/defaultrouter file has appropriate gateway
4. FW-1 is running (I've stopped (forwarding goes off) and restarted it)

Anything obviously out of whack? Any help would be greatly
appreciated...

Thanks, Joe
-- 
In theory, theory and practice are the same; 
In practice, they're not even close!


References:
Indexed By Date Previous: looking for a solution
From: ken ng <ken @ helios . njit . edu>
Next: RE: SATAN mailing list interest?
From: "LoRd oRiOn" <mindbenders @ hotmail . com>
Indexed By Thread Previous: Re: [FW1] Firewall 2.1 , Solaris and rouing
From: JERALD JOSEPHS <jerald . josephs @ Sun . COM>
Next: Re: [FW1] Firewall 2.1 , Solaris and rouing
From: Ryan Russell/SYBASE <Ryan . Russell @ sybase . com>

Google
 
Search Internet Search www.greatcircle.com