Re: PIX: When do config changes take effect?

2001-12-13 Thread Jay Christopherson
Yep, in nearly every case I have encountered, simply making the change itself applies the change (i.e. to ACL, NAT, etc...). Saving to mem (wr mem) merely confirms the fact that when the PIX *is eventually* reloaded (hopefully after months and months, no YEARS... lol...) of uninterrupted and bug

Re: PIX: When do config changes take effect?

2001-12-13 Thread Daniel Crichton
On 13 Dec 2001 at 1:08, Jay Christopherson wrote: Yep, in nearly every case I have encountered, simply making the change itself applies the change (i.e. to ACL, NAT, etc...). Saving to mem (wr mem) merely confirms the fact that when the PIX *is eventually* reloaded (hopefully after months

mutihomed machine route problem

2001-12-13 Thread Michael Zhao
Hi , My former network structuer is as following : outside | fw | Cisco switches | | | WSs SRVs I want add another net segments to my net. I insert two NIC interfaces on my windows nt server 4.0 system ( sp 6a). One NIC connect to switches via the normal cable , and another one connect to a

RE: simple question

2001-12-13 Thread Hiemstra, Brenno
Did you configure the windows machine to make the arp entry public ? In solaris you can do this my adding pub at the end of the static arp line... local.arp should do this for win2k (if I got it right) but did you also stop and start the firewall when you altered something in the local.arp ?

RE: simple question

2001-12-13 Thread Claussen, Ken
I think you want to specify the MAC address of the NIC in the firewall which should respond on behalf of the IP in the file local.arp. As opposed to putting the actual MAC address of the Server NIC. Otherwise the firewall does not know on which interface to proxy arp for this server. So yes it

Re: mutihomed machine route problem

2001-12-13 Thread bob bobing
If you really want some help on this you are going to have to post route info, and ip/network info. like what are all the network/netmask involved. Have you updated the firewall rules, what does you firewall log etc etc etc. ... so sleepy stimpy ... --- Michael Zhao [EMAIL PROTECTED] wrote: Hi

vpn for Pix

2001-12-13 Thread Barry Hudson
Could someone recommend a good site or readme for setting up vpns on a Pix 515. TiaBarry S. Hudson Senior PC/Network Analyst, AVP Second Bank and Trust Business Email [EMAIL PROTECTED] ___ Firewalls mailing list [EMAIL PROTECTED]

pop server timeout

2001-12-13 Thread Matt Gorham
I have a number of machine that connect to the internet and mailservers via a netscreen 5xp and a adsl connection. The 5xp obtains its untrusted ip from a dhcp. I So if I have no traffic the adsl connection is dropped and the clients cannot get there mail until they close there mail

FTP Authentication (was: RE: Pix FW)

2001-12-13 Thread Brian Ford
Mark, Lets say I have a anonomous ftp connection, instead of seeing only disallowed packets (all packets except ftp) I would like to see the allowed packets to that server as well (which would be the ftp in this case), in order to see who is connecting. I guess I don't get it. Why not

Re: Router problem?

2001-12-13 Thread Brian Ford
Laura, I think you are correct and this is not a firewall problem. I'd check to make sure the configuration of your router didn't change when you replaced hardware (the T-1). Sometimes during the tuning process a router gets configured properly but the configuration doesn't get written to

RE: NetGear FR314/PPPoE possible routing problem

2001-12-13 Thread Palmer, L. Guy
Does anyone know of a Personal Firewall (i.e. low cost appliance) which can accomodate both USB and ethernet connection types ?? Specifically, I need on for a mobile office which will have a satellite broadband link (USB in) and protect a PC on our intranet (ether out) Thanks a ton, for any

Router Problem (revisited)

2001-12-13 Thread Laura Folden
Thanks to everyone for their input. Turns out it wasn't the router at all; the switch that connects firewalls to the router was damaged by the strike and was chewing up packets. I replaced the switch and will get a better UPS, and we're running fine right now. Thank you Laura Folden

RE: Whether a port is Firewalled or just not opened

2001-12-13 Thread Suzanne . VanPatten
I agree nmap will show filtered if there is an access-list or firewall in front of the machine. However, I interpreted the email to mean you are firewalling a single machine on that machine itself?? If so, I believe nmap will only know that that machine is listening on port 80. Nmap simply does a

Re: linux/iptables firewall w/multiple dmzs

2001-12-13 Thread Tony Carter
Please disregard... Wrong list... -Tony On Thursday 13 December 2001 10:46 am, Tony Carter wrote: Hello All, Has anyone used Linux/iptables in a scenario where you have multiple DMZs, with each DMZ serving multiple servers (web,email,...) and the linux box has an IPSEC tunnel between itself

RE: Whether a port is Firewalled or just not opened

2001-12-13 Thread Paul Robertson
On Thu, 13 Dec 2001 [EMAIL PROTECTED] wrote: I agree nmap will show filtered if there is an access-list or firewall in front of the machine. However, I interpreted the email to mean you are firewalling a single machine on that machine itself?? If so, I believe nmap will only know that that

RE: vpn for Pix

2001-12-13 Thread Clinch, Adam
Why not cisco's top issues for PIX vpns ?? http://www.cisco.com/warp/public/471/top_issues/vpn/pixvpn_index.shtml Ad, -Original Message- From: Barry Hudson [mailto:[EMAIL PROTECTED]] Sent: 13 December 2001 14:17 To: [EMAIL PROTECTED] Subject: vpn for Pix Could someone recommend a

Radius log analyser

2001-12-13 Thread Pinel Pierre-Marc
I need to produce an history for the use of a RAS. I focused on Radius. Does anybody knows a log analyser/parser for radius for win32? ___ Do You Yahoo!? -- Une adresse @yahoo.fr gratuite et en français ! Yahoo! Courrier :

Re: Fw: NetGear FR314/PPPoE possible routing problem (Mike Fetherston)

2001-12-13 Thread Lauren Horn
Message: 8 = From: Mike Fetherston [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Fw: NetGear FR314/PPPoE possible routing problem Date: Thu, 13 Dec 2001 09:12:50 -0500 ...You can try lowering the MTU on your client machines

Re: portmap / rpc behind a firewall

2001-12-13 Thread dgillett
On 13 Dec 2001, at 15:54, Suleyman Kutlu wrote: Hi everybody. The question below may seem to you stupid, but I am not an expert on RPC stff. In on of our customers, I have two machines running softwares communicating eachother via RPC. One of the machines is on Intranet (secure network)