Sunscreen 3.2 / Stateful UDP

  • Permalink
  • submit to reddit
  • Email
  • Follow


I'm running Sunscreen 3.2 (routing mode) on Solaris 9 with only one
public IP address (using hme0). I've got a local network
192.168.1.0/27 (using znb0).  I also have one DMZ
192.168.1.224/27 (using znb1). Since Sunscreen doesn't support
port forwarding I've statically NAT'd the external IP to DMZ host
and have two packet filter rules that allow SMTP in/out for that
host.  Currently the internal net is being NAT'd using Dynamic mode on the
Screen. This works fine and all TCP traffic is tracked via the statetable.
But, UDP is not. For example, I have a Cisco VPN client machine on the
internal net and when using UDP for encapsulation of ESP packets none
of the returning UDP packets are passed back to the Cisco VPN host (using
a hub and sniffer in front of the Screen's hme0 interface).  Although both
'ssadm lib/statetables' and ssadm lib/nattables' have the communication
properly listed; nothing is even logged as being passed or dropped on hme0
interface. Detailed logging is enabled for everything except broadcast &
NetBIOS type traffic.  If I switch the Cisco VPN client to use TCP for esp
encapsulation everything works.  I tried other udp communications like
ntp, but no luck. The only UDP that's works is DNS. Anyone have similar
experiences with Sunscreen? Maybe know the cause here and/or even a
solution?

Thanks in advance.

0
Reply Techniq 10/11/2003 9:02:34 PM

See related articles to this posting

comp.sys.sun.admin 3732 articles. 4 followers. Post

0 Replies
179 Views

Similar Articles

[PageSpeed] 36


Reply:

Similar Artilces:

sunscreen 3.2 difficulties
Hello, Since installing SunScreen 3.2 on solaris9 sparc, network connectivity has been dismal. The rules are configured with minimal logging and it isn't creating a noticeable load on the system, which is barely in use now as it is. Since the install of SunScreen, SSH connections to the machine are constantly interrupted by long pauses at random intervals, and they last random periods of time, from 2 to 60 seconds. I have connected to this machine from different networks, and I get the same result. When I connect via the RSC card, there is no lag. It has been working fine for years - ...

SunScreen 3.2 +snmp
Hello! I'm trying to get snmp info from SunScreen 3.2 Lite firewall, but with no result. Anybody knows any good documentation about it. In admin manuals from docs.sun.com there is just configuring snmp receivers. I installed Net-snmpd, and trying to use for that. I'm running Solaris 9 in a sparc machine. -- Thanks, Timo Leppiniemi ...

Sunscreen 3.2 or Ipfilter
Hi, I have been reading all the threads concerning firewalls for Solaris and for the most part they are all dealing with NAT and more complicated issues. I have one Solaris 9 box hooked up to a static (public IP) DSL line - all I need to do is block all but http & SSH, which product would be recomended in this situation? Chris HI, Chris Wall wrote: > Hi, > I have been reading all the threads concerning firewalls for Solaris and for > the most part they are all dealing with NAT and more complicated issues. I > have one Solaris 9 box hooked up to a static (public IP) DSL li...

firewall, SunScreen 3.2 Solaris9 and dhcp
Im i right Sunscreen 3.2 does not support dhcp. when i connect to my isp i do "ssadm activate Initial.XX" via a script. and sunscreen compiles/reloads the adresses for the dhcp interface and the firewall are working ok. my question is, are there something automagic for dhcp one can do ? /J�rgen ...

Solaris 9 and Sunscreen 3.2 Stealth Mode
Hi, I've got a Sun V100 running Solaris 9 08/03 which I would like to run Sunscreen 3.2 on. I've updated the system, installed all of the Sunscreen pre-requisite patches etc and the Sunscreen software. I would like to run this in stealth mode, where dmfe0 will be the interface pointing to the outside world, and dmfe1 will point to the inside. Currently, I only have dmfe1 configured with an IP for administrative purposes (as required). For dmfe0, is it sufficient to simply have a blank /etc/hostname.dmfe0? I don't want the firewall to have an IP address. Afterwards I assume its po...

duplicate Interface error when activating policy in SunScreen 3.2
Hi all, I have a Solaris 9 box with 2 network interface on connected to different networks. SunScreen 3.2 was installed with local admin and basic firewall config set to Routing mode. WHen I tried to start the policy I get an error "duplicate interface rf0". Does anyone knows how to resolve this? Thanks Ldd ...

[ANN] SMC
SMC - The State Machine Compiler v. 3.1.2 Requires: Java 1.4.1 SE (Standard Edition) or better. Download: http://sourceforge.net/projects/smc Home Page: http://smc.sourceforge.net ================================================================= What's New? ================================================================= (No new features.) ================================================================= Bug fixes ================================================================= + (-csharp) Incorrectly placed a state's entry actions where the exit actions should have been....

[ANN] SMC
SMC - The State Machine Compiler v. 3.2.0 Requires: Java 1.4.1 SE (Standard Edition) or better. Download: http://sourceforge.net/projects/smc Home Page: http://smc.sourceforge.net ================================================================= What's New? ================================================================= + Added -graph option which generates a Graphviz/DOT representation of the .sm finite state machine. ================================================================= Bug fixes ================================================================= + (Ant examples) C...

Re: BIND 9.3.0
> Hello Mark, > Sorry for replying late. > > Mark Andrews wrote: > > > Hey all, > > > Thankfully, i got this solved. This was happening becuase my OS > does > > > not support sending/recieving control messages (CMSG*) via > sendmsg() > > > and recvmsg() calls. > > > > > > Thus a call to recvmsg() in the code was returning EINVAL. > > > > > > If you ever face this problem then undefine "USE_CMSG" (i.e. #undef > > > USE_CMSG) in the file lib/isc/unix/socket.c. This will d...

Request TCM rate 2/3 64 state convolutional encoder(8PSK)
I just see the Ungerboeck's paper in 1981. It provided a 64 state encoder, but represented in H.... where i can find a G version..... A figure presentation is better....thx a lot!! P.S. I need the non-recursive encoder... The H in Ungerboeck's paper is RSC type.. ...

[ANN] SMC
SMC - The State Machine Compiler v. 4.3.0 Requires: Java 1.4.1 SE (Standard Edition) or better. Download: http://sourceforge.net/projects/smc Home Page: http://smc.sourceforge.net ================================================================= What's New? ================================================================= + Added -reflect option for Java, C#, VB.Net and Tcl code generation. When used, allows applications to query a state about its supported transitions. Returns a list of transition names. This feature is useful to GUI developers who want to enable/...

[9fans] acme: dirty state after 1-2, 1-3 click in a tag line
Hello, I've noticed two strange things about acme: 1) when I snarf the name (or a part of it) of a file with a mouse (in the tag line) using 1-2, 1-3 mouse chord, the file is marked dirty. (I think it should not.) 2) i) when I open a win window, 'win' appears in the topmost tag line (if you open 2 such windows, there will be 2 'win's) (Why?) ii) when I Dump the state and there is a win window, after Exiting and starting 'acme -l thedumpfile' there is an extra 'win' text added to the topmost line. Could somebody comment on these, please? Is this behaviou...

RE: [ace-users] Limit for MIOP request size and UDP packet size #2 #3
This message is in MIME format. Since your mail reader does not understand this format, some or all of this message may not be legible. ------_=_NextPart_001_01C3738C.000ACF70 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hi all, I haven't seen any side effects until now. Everything works : previous MIOP requests whose size are about 9Ko are = now transmitted and received. Although my need is only for 32 Ko max, I'm just wondering why it is = not portable to set ACE_MAX_DGRAM_SIZE to the UDP datagram max size which is 64 Ko ??...

Solstice X.25 9.2 Link status: LAPB Link 0 is in state ADM #3
Hy all, I have a problem when I am trying to start the x.25 network. I have a temporary license, so I have to install a new valid license file each month. It has always worked fine until now. This last time, when I pulled down the Network Menu (of the x25tool) and clicked on Start X.25, I checked that the link status (using linkstate application) was in the following state (instead of the NORMAL state): Mon Oct 24 09:52:28 2005: LAPB Link 0 is in state ADM Do you know what should be the problem? How can I resolve it? Thank you very much ...

how can i write this statement labels=[1;1;1;1;1;1;1;1;1;1;1;1;1;1;1;1;1;1;1;1;1;1;1;1;2;2;2;2;2;2;2;2;2;2;2;2;2;2;2;2;2;2;2;2;2;2;2;2;3;3;3;3;3;3;3;3;3;3;3;3;3;3;3;3;3;3;3;3;3;3;3;3;]; in compress fo
How to write it in compact form to avoid repetition "shah " <shahkhn3@gmail.com> wrote in message <lodugh$8hr$1@newscl01ah.mathworks.com>... > How to write it in compact form to avoid repetition You'll find in this thread different solutions for similar question http://www.mathworks.fr/matlabcentral/newsreader/view_thread/335814 Bruno ...

Bain de Soleil Orange Gelee Sunscreen, SPF 4, 3.12-Ounce Bottles (Pack of 2)
Price:$19.98 Image: http://discountadvisor.info/image.php?id=B001EJOO6M Best deal: http://discountadvisor.info/index.php?id=B001EJOO6M I've used this product for years and have had trouble locating it locally. Thanks goodness amazon had it. I bought it in bulk! It gives me the best tan, nothing compares. This product is the best...have used for over 20 years and you truly do get that tropics bronze tan.......even has a little spf which you really should use a 15 at least....love...love...love This is the ONLY sunscreen my wife uses. Not easy to get in our place, her problems ended...

get gateway p-7811 fx or wait 2-3 years for a laptop with solid state hdd and advanced wireless?
Hi, I'm thinking of getting the gateway p-7811 fx. My old laptop is fine, but with this one I could play some newer games and it's supposed to be a super deal (about 1.4k). On the other hand new technologies like solid state hdd and more advanced wirless (don't remember what it's called, but it's range is supposed to be greater than what's currently used and it's supposed to be faster) that i would like sound like they are around the corner and could soon be common on laptops. I'd be willing to wait 2-3 years for a laptop for about 2.5 k with these features, r...

[1 1 1 1 1 ;2 2 2 2 2 ;3 3 3 3 3 3;....;n n n n n]
Hi, Anybody knows how to create this matrix but without using any loops? a=[1 1 1 1 1 ;2 2 2 2 2 ;3 3 3 3 3 ;.......;n n n n n ] Thank you. Hana. Hana wrote: > Hi, > Anybody knows how to create this matrix but without using any loops? > a=[1 1 1 1 1 ;2 2 2 2 2 ;3 3 3 3 3 ;.......;n n n n n ] HELP REPMAT - Randy Hana wrote: > > > Hi, > Anybody knows how to create this matrix but without using any > loops? > a=[1 1 1 1 1 ;2 2 2 2 2 ;3 3 3 3 3 ;.......;n n n n n ] > > Thank you. > Hana. Hope this isn't homework. >> repmat([1:n]'...

Aix 5.2 and gcc 3.3
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Any bleading edgers out there get this to work? Building with BerkeleyDb 4.1.25 and TLS Had some problems with propolice (stack smashing protection) causing gcc to fail. Removed that option and now it compiles but won't link... yeah I know AIX what's new? The configure script for newdb had some of the same errors while testing for mutex's but eventually found configure:17733: result: UI/threads/library Fails with ld: 0711-317 ERROR: Undefined symbol: .mutex_init ld: 0711-317 ERROR: Undefined symbol: .cond_init ld: 0711-317 ERRO...

Upgrade from VO 1 - 2 - 2..1 -2.2 - 2.3 -2.4 - 2.5 - 2.6 - 2.7
About upgrade 2.5 - 2.7 at $ 384.00 For most products I'm using - the updates (2.0 - 2.1 - 2.7) are free... 2.0 to 3.0 might be worth + 10-30% of the original price? VO is + full price again & again - Full program price for every minor upgrade/bug-fix? I dropped out of the money/bugs [VO] at 2.5 after starting at 1.0 more than 10 years ago. Certainly whoever is making VO have to make a living; earning moneys: - that is OK! A 10 years old VO site; - 10 years later, how much have changed? http://www.yi.com/prany/cavo/cavofront.htm Even MS is not ...

compiling gcc 3.2.3 on aix 4.3.2 using gcc 3.2.1
All, I am trying to compile gcc-3.2.3 on aix-4.3.2 using a prebuilt gcc-3.2.1. I am using GNU make, native as,ar,ld. There are the errors I get. Can anyone help? thx balaji $ gmake bootstrap gmake[1]: Entering directory `/mnt/gcc-3.2.3/aix/libiberty' gmake[2]: Entering directory `/mnt/gcc-3.2.3/aix/libiberty/testsuite' gmake[2]: Nothing to be done for `all'. gmake[2]: Leaving directory `/mnt/gcc-3.2.3/aix/libiberty/testsuite' gmake[1]: Leaving directory `/mnt/gcc-3.2.3/aix/libiberty' gmake[1]: Entering directory `/mnt/gcc-3.2.3/aix/zlib' : gmake ; exec true "AR_...

how to convert union(2*x+y=3,3*x+2*y=5) to {2*x+y=3,3*x+2*y=5}
Thanks! In article <1140494713.980133.168190@f14g2000cwb.googlegroups.com>, loric <dr.huiliu@gmail.com> wrote: >Thanks! It isn't clear exactly what your question is, but: > `union`({2*x+y=3},{3*x+2*y=5}); {2 x + y = 3, 3 x + 2 y = 5} > Union := proc() { seq( `if`(s::'set',op(s),s), s=args ) } end proc: > Union(2*x+y=3,3*x+2*y=5); {2 x + y = 3, 3 x + 2 y = 5} > Union(2*x+y=3,{3*x+2*y=5}); {2 x + y = 3, 3 x + 2 y = 5} ...

ANN: ActivePython 2.3.2 & ActivePython 2.2.3
We are pleased to announce that versions 2.3.2 and 2.2.3 of ActivePython are now available for download from: http://www.ActiveState.com/ActivePython ActivePython 2.3.2 is the first ActivePython release for the Python 2.3.x series. ActivePython 2.2.3 is a bugfix release for, and supercedes, ActivePython 2.2.2. ActivePython is ActiveState's quality-assured binary build of Python. Builds are currently available for Windows, Linux and Solaris. In addition to the core language, ActivePython features: * zlib and bzip2 for data compression; * Tkinter for Tk development; * a lar...

ANN: ActivePython 2.3.2 & ActivePython 2.2.3
We are pleased to announce that versions 2.3.2 and 2.2.3 of ActivePython are now available for download from: http://www.ActiveState.com/ActivePython ActivePython 2.3.2 is the first ActivePython release for the Python 2.3.x series. ActivePython 2.2.3 is a bugfix release for, and supercedes, ActivePython 2.2.2. ActivePython is ActiveState's quality-assured binary build of Python. Builds are currently available for Windows, Linux and Solaris. In addition to the core language, ActivePython features: * zlib and bzip2 for data compression; * Tkinter for Tk development;...