Sunscreen 3.2 / Stateful UDP

I'm running Sunscreen 3.2 (routing mode) on Solaris 9 with only one
public IP address (using hme0). I've got a local network
192.168.1.0/27 (using znb0).  I also have one DMZ
192.168.1.224/27 (using znb1). Since Sunscreen doesn't support
port forwarding I've statically NAT'd the external IP to DMZ host
and have two packet filter rules that allow SMTP in/out for that
host.  Currently the internal net is being NAT'd using Dynamic mode on the
Screen. This works fine and all TCP traffic is tracked via the statetable.
But, UDP is not. For example, I have a Cisco VPN client machine on the
internal net and when using UDP for encapsulation of ESP packets none
of the returning UDP packets are passed back to the Cisco VPN host (using
a hub and sniffer in front of the Screen's hme0 interface).  Although both
'ssadm lib/statetables' and ssadm lib/nattables' have the communication
properly listed; nothing is even logged as being passed or dropped on hme0
interface. Detailed logging is enabled for everything except broadcast &
NetBIOS type traffic.  If I switch the Cisco VPN client to use TCP for esp
encapsulation everything works.  I tried other udp communications like
ntp, but no luck. The only UDP that's works is DNS. Anyone have similar
experiences with Sunscreen? Maybe know the cause here and/or even a
solution?

Thanks in advance.

0
Techniq
10/11/2003 9:02:34 PM
comp.sys.sun.admin 3736 articles. 0 followers. bozothedeathmachine16 (49) is leader. Post Follow

0 Replies
237 Views

Similar Articles

[PageSpeed] 8
Reply:
Similar Artilces:

AIX 4.3.3 on Powerstation 365
I was just given a IBM Powerstation 365 and a copy of AIX 4.3.3, when I boot from the CD-ROM the system will crash almost instantly. Is this version of AIX supported on this system? I have been having a hard time finding this myself. I found a couple references that I might be able to run it without graphics support if I could find a firmware update for it. Thanks, Michael Spoonified schrieb: > I was just given a IBM Powerstation 365 and a copy of AIX 4.3.3, when > I boot from the CD-ROM the system will crash almost instantly. > Is this > version of AIX supported on this system?...

US-TX-Austin: Applications Eng., 3+yrs exp., Reference board design, PCB layout; (45332357602)
US-TX-Austin: Applications Eng., 3+yrs exp., Reference board design, PCB layout; (45332357602) ============================================================================================== Position: Applications Eng. Reference: SMC01779 Location: Austin TX Duration: Perm Skills: BSEE and 3+ years experience Exp with reference board design, using schematic capture programs and familiarity with PCB layout software. Knowledge of proper PCB layout principles for analog signal, ESD, and EMI integrity. ...

Re: stats jargon
Paul, Did you get it right? Possibly, possibly not! I think it is more than just "considering the effects of AGE" and more like: given your data (regardless of its validity) removing any effect(s) that MIGHT be mathematically related to AGE. Art ----- On Thu, 1 Jan 2009 14:24:41 -0800, paul wilson <paulwilsn@YAHOO.COM> wrote: >so what you're saying is that "controlling for the effects of AGE" means "considering the effects of AGE"? >Did I get it right? > > > > >________________________________ >From: Wensui Liu <liuwensui@...

Re: Oracle Rdb on GS1280 with 7.3-2 exceeds 1 million transactions per #10
>From: young_r@encompasserve.org (Rob Young) >X-Newsgroups: comp.os.vms >Subject: Re: Oracle Rdb on GS1280 with 7.3-2 exceeds 1 million transactions per >Date: 15 Jan 2004 02:47:13 -0600 > Nice post, really. Before you think I'm blasting you... I'm not. > It may be as simple as you are nickel/dime compared to big customers > that want the other behavior - always. For instance, JSTARS. I > imagines JSTARS flys through many timezones many times a day. The > only thing that matters to them is system time (or UTC). Clusters > spanning timezones that a...

Bind 9.2.3 ignores listen on option #3
named.conf contains: options { directory "/etc/named"; listen-on { 192.168.0.0/16; 127.0.0.1; }; listen-on-v6 { none; }; allow-query { 192.168.0.0/16; 127.0.0.1; }; version "Go away!"; }; Yet the following is logged on startup: Jan 30 17:58:27 brickwall named[2870]: starting BIND 9.2.3 -u named -t /var/named/chroot Jan 30 17:58:27 brickwall named[2870]: using 1 CPU Jan 30 17:58:27 brickwall named[2870]: loading configuration from ...

ANDREW E15S09P49 | Looking to Buy | Launch 3 Telecom
Launch 3 Telecom is buying the following part: ANDREW E15S09P49 AWS/PCS TMA WITH 700-850 BYPASS (TWIN) Request a Quote: http://www.launch3telecom.com/buying/Andrew/E15s09p49.html www.launch3telecom.com | 1-877-878-9134 Launch 3 Telecom has been responsible for distributing wireless and wireline equipment around the globe. We take pride in individually personalizing our relationship with the customer while remaining globally connected. r Follow us on: Wordpress: http://blog.launch3telecom.com/ Blogger: http://launch3telecom.blogspot.com/ Pinterest: http://pinterest.c...

compilation problem in g++ 3.4.3
I was not able to compile the following code on g++ 3.4.3. g++ 3.3.2 happily accepted the code. Can someone help me why this code does not compile in g++ 3.4.3? enum TYPES { A, B }; template <TYPES v> struct Test { static int i; }; int Test<A>::i = 1; int Test<B>::i = 2; int main() {} --lsu ps: [suresh@archer pint]$ g++ -o a a.cpp a.cpp:8: error: too few template-parameter-lists a.cpp:8: error: expected `,' or `;' before '=' token a.cpp:9: error: too few template-parameter-lists a.cpp:9: error: expected `,' or `;' before '=' token ...

Callable IDL #3
Hello, I have been using Callable IDL from a Windows app for over a year now. Some modifications were made to the program and suddenly we're getting lots and lots of "Error From IDL" pop-up dialogs. Each dialog displays a line of text that would normally be printed to the log window if the IDL script were run from the IDL IDE (e.g. "% Compiled modlue: MY_MODULE"). I can't find a reference to these dialogs in the IDL manuals, and I would like to know if anyone else has gotten these messages. Thank you, Jim Brown ...

java fun, and new sunscreen gui
Some random little announcements: 1. After waiting waaay longer than I originally intended, I am now starting to write an actually USABLE sunscreen GUI. A standalone one, that does require you to run a webserver and a browser to do anything with it. Anyone want to help? 2. In support of this, I have made an interesting little java component. I call it a "Listor" class. It's AWT based, so is small, fast, and will run on just about anything. It displays "lists" of lines. But unlike the java "List" class, it assumes that each line has...

Yellowfin Release 3.3
Yellowfin Release 3.3 Announcement Yellowfin is delighted to announce the content for our upcoming release 3.3. Scheduled for release end of November 2007, Yellowfin 3.3 will bring further ease of use to reporting and analytics for both embedded and stand alone reporting users. Release 3.3 will certainly improve the ability to interact with, and visualise your data. This will be achieved through greater flexibility and functionality in dashboard design, report grouping and general formatting. Naturally additional administrative features will make Yellowfin even easier to maintain and embed in...

Mail Merge for Microsoft Access 2007 2.0
4TOPS Mail Merge for Microsoft Access is the ultimate solution if you want to create Microsoft Word documents or emails using data in your Microsoft Access database. Documents can be created easily with any level of complexity (e.g. contracts). Selectively producing documents is as easy using selecting the records using filters and record selectors. Supports email mail merge, labels and envelopes, directory reports and listings. Mail Merge is one of the main type of uses in any administrative software application. It is used extensively in all industries, typically by Access users that...

SN#19188 Sun Java System Web Server 7.0 Update 2
SYSTEM NEWS FOR SUN USERS Vol 118 Issue 4 2007-12-24 Article 19188 from section "Software" Full Product Install Features Performance Improvements and Much More Download for free the full product installation of the Sun Java System Web Server 7.0 Update 2 that comes with a PKCS-11 bypass feature to achieve better SSL performance out-of-the-box, more administration options, Solaris Management Framework (SMF) integration, certification on Red Hat Enterprise Linux 5, and much more. Details at http://sun.systemnews.com/g?A=19188 ...

Call for Participation
Call for Participation 19th Annual Conference for Software and Systems Process (SEPG 2007) Theme: Transforming Performance: Products, People, and Business Austin, Texas U.S.A. March 26-29. 2007 Web: http://www.sei.cmu.edu/sepg/2007/ *** All inquiries to customer-relations@sei.cmu.edu *** The Software Engineering Conference for Software and Systems Process (SEPG) is the world's leading annual conference and exhibit showcase for process improvement. Now in its 19th year, the conference brings together international representatives from government, industry, and academia for a...

Re: Setting up printers on an HP3000 using DNS #3
Joe, DNS is probably the best way to go. You can go through NPconfig (if memory serves me right ) or through a third party setup like ESPUL's PrintPath. Remember your days at HNS... Chuck Ciesinski ----- Original Message ----- From: "Joseph Dolliver" <j.dolliver@worldnet.att.net> To: <HP3000-L@RAVEN.UTC.EDU> Sent: Friday, January 14, 2005 12:09 PM Subject: [HP3000-L] Setting up printers on an HP3000 using DNS > Is it possible to setup printers on an HP3000 system using DNS? > > I have heard from my client that HP staff have told them no w...

Re: Spam Issues #2
In article <telecom23.176.16@telecom-digest.org>, SELLCOM Tech support <support@sellcom.com> wrote: > I believe that we are all against spam, but what about when a > lackhole type site is being run in a totally irresponsible manner? > The trash running http://www.five-ten-sg.com/blackhole.php have whole > sections of the world blocked without any real cause and they won't > remove such listings after notification. > We had a customer place an order for a phone and our reply to them was > "blacklisted by FIVETEN". > Can anything...

Trimmed means #2
Hi David, This is the point. The weights change over time.=20 Any hint? Thanks in advance=20 Rick ...

data access page #3
hi ! i have designed a data access page and it works fine connecting to the database on my computer but when i change the connection to connect to my database on my web server it wont connect.the database on my website works fine with connections using Frontpage but wont work with a data access page ?? thanks ...

lock user account on aix 4.3.3
hello , how can i lock user account , who didn't login for 45 days ? ariec ariec wrote: > hello , > > how can i lock user account , who didn't login for 45 days ? > > ariec ariec, If you want this to be automatic you will have to create a script to parse the /var/adm/wtmp file every night and lock out all users or specific users that have not logged in in 45 days. Or you can change the password configs to expire user's passwords after 6 weeks. The setting is maxage and maxexpired in the /etc/security/user file. You can change them for every user on the syst...

VueScan & raw files #2
--=-=-= Content-Transfer-Encoding: quoted-printable Hi! Yesterday while googling I found an old thread in pcreview's forums named "VueScan raw file is not a true raw file!". Tried to post there 'cause it was too old to be found on news server, but since I did not receive any reply I'm reposting here... I'm new Epson V700 user preparing to batch-scanning ~2500 slides and the old thread was discussing whether VueScan apply some processing on its faw files... <quote> Originally Posted by Henk de Jong My conclusion is: 1) With ICC Built-in ...

Commodore FTP Sites Listing -- Last update 25 April 2010 #3 202511
Last Change/Update: 25 April 2010 =================== A +++ before an entry indicates that the entry is new, or has been updated, or has changed, since the last Listing. A --- before an entry indicates that the _prior_ entry was removed from the list, since the last Listing. A ??? before an entry indicates that the entry resolves, but does not connect. The number next to it indicates the first report from which this problem has been open. A host that does not connect with 6 months of reported downtime or more will be deleted on the next report. Please report if this host i...

data extraction #3
hello my problem is i think i have loaded a text file with importdata on matlab but now i would like use just several lines of this text file how do I do? thanks ...

US-PA: Bala Cynwyd-Applications Developer 3
************************************************************** JobCircle.com is the largest regional job board in the Mid-Atlantic region, with tens of thousands of job offerings in PA, NJ, DE, MD, NY, and Washington D.C. To learn more, visit http://www.jobcircle.com?source=ng ************************************************************** Job Title: Applications Developer 3 Job Location: PA: Bala Cynwyd Pay Rate: Open Job Length: full time Start Date: 2009-02-09 Company Name: Oracle Contact: Human Resources Phone: email only please Fax: ...

[9fans] (no subject) #2 #30
Subject devsegment #g doesn't seem to work. is this a relic predating the segattach system call? - erik It's optional; you need to add segment in the `dev' section of your kernel configuration. It has worked when I've used it. ...

[News] A Look at Thunderbird 3 and Many Extensions
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 A leap forward - Thunderbird 3 beta ,----[ Quote ] | From the outside it’s just another Thunderbird as we know it - with some user | interface changes and tweaks. But under the hood, the groundwork was laid for | many future improvements and additions. The bird will have the Lightning | calendar offered as a default installation option in its final version - and | with it introduce you to tabs. Yes, tabs as we know it from Firefox - now in | the upcoming new Mozilla product for email, messaging, calendaring and | whatnot. `---- https...

Dungeon siege 2 help
how the hell do I play this game, i'm beta testing it and i have no idea how to play it, ive never played dungeon siege 1, would someone please help with some sort of basic instructions. thanks in advance Cheers Stone Monkey On 03 Jun 2005 20:08:00 GMT, Stone Monkey <tenny2k@NOSPAMrtennant.fsnet.co.uk> wrote: >how the hell do I play this game, i'm beta testing it and i have no idea >how to play it, ive never played dungeon siege 1, would someone please help >with some sort of basic instructions. thanks in advance Perhaps you would be better off asking other DS2 ...