Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Urgent - NT 4 Routing

Thread Tools
 
Search this Thread
 
Old 07 August 2003, 04:48 PM
  #1  
shunty
Scooby Regular
Thread Starter
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Post

Hi all

I have one of my guys in Italy trying to configure a checkpoint firewall...

NT routing is sha55ed I reckon.....IP forwarding is enabled but no IP traffic is going out through this server.
tried route -f & reboot, can you add static public IP data to the NT4 routing table ??

cheers

shunty
Old 07 August 2003, 04:54 PM
  #2  
shunty
Scooby Regular
Thread Starter
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Post

I think IP is knackered...going to reinstall it now...
tried different nics.....

shunty
Old 07 August 2003, 06:24 PM
  #3  
ids
Scooby Regular
 
ids's Avatar
 
Join Date: May 1999
Posts: 424
Likes: 0
Received 0 Likes on 0 Posts
Post

Shunty,

NT4 or Win2K ?? If its NT4 - i'm not supprised as its a pile of poo with multiple nics and CP FW-1.

Wouldnt supprise me if its a problem with the binding order of the nics. You need to make sure the interface/IP that the firewall object has been created as, responds to 'hostname' at the command prompt. Better on NG, I must admit.

As for routes then yeh. All you need to use is 'route add -p destadd mask netmask nexthop metric' - obvoius I know

The -p make the route permanent upon reboots

Ids
Old 07 August 2003, 06:38 PM
  #4  
stevem2k
Scooby Regular
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Post

Firewalls on NT what will they think of next.

There's a decent red hat implementation of NG about now you know .....


Steve
Old 07 August 2003, 06:43 PM
  #5  
ids
Scooby Regular
 
ids's Avatar
 
Join Date: May 1999
Posts: 424
Likes: 0
Received 0 Likes on 0 Posts
Post

Steve

its been around ages.... and most large orgs have stopped using it.

Shunty

To be honest on Intel kit, you would be better off running Secure Platform which is a hardened RedTwat Linux. Far easier to manage than on Windows and more performant. For less experianced users there is a command menu system or browser interface, for the beardy, pony tailed, flip floppers there is the usual command line interface.

Better still get some Nokia appliances. They are sweeeet

If you need any more help then post it up... dont mind as I have sweated long and hard over bl00dy NT and FW1 combos' in the distant past.

Ids
Old 07 August 2003, 06:55 PM
  #6  
shunty
Scooby Regular
Thread Starter
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Post

ids - you still there mate ??

shunty
Old 08 August 2003, 09:35 AM
  #7  
shunty
Scooby Regular
Thread Starter
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Unhappy

built a new server (different nics & cables) on NT with no firewall on just to test IP routing.
On both servers you can ping the external interface of the firewall from the internal clients & you can also ping the external interface of the firewall from the internet BUT no traffic can get in or out from this interface ???

got to be a routing issue ??

any other ideas

shunty
Old 08 August 2003, 01:13 PM
  #8  
Jeff Wiltshire
Scooby Regular
 
Jeff Wiltshire's Avatar
 
Join Date: Nov 2000
Location: 412 Wheel HP Audi RS4
Posts: 2,021
Likes: 0
Received 1 Like on 1 Post
Post

Have you got IP Forwarding enabled on the new server ?

[Edited by Jeff Wiltshire - 8/8/2003 1:14:39 PM]
Old 08 August 2003, 01:33 PM
  #9  
ids
Scooby Regular
 
ids's Avatar
 
Join Date: May 1999
Posts: 424
Likes: 0
Received 0 Likes on 0 Posts
Post

Shunty,

As Jeff says you need IP forwarding on. On NT4 there is a tab to tick, if its Win2K then a registry key.

My rule of thumb is get the box routng correctly before installing/activating the firewall applications.

Ids
Old 08 August 2003, 01:37 PM
  #10  
ids
Scooby Regular
 
ids's Avatar
 
Join Date: May 1999
Posts: 424
Likes: 0
Received 0 Likes on 0 Posts
Post

Also...

If IP forwarding is on make sure that only one NIC has a default gateway configured (on the Interface properties). This is usually your 'outside' interface facing out to the Internet.

All other routes need to be configured as statics. On W2K its not so bad (and sometimes works) but NT4 it can cause some issues if more than 1 NIC has a default gateway.

Ids
Old 11 August 2003, 11:44 AM
  #11  
shunty
Scooby Regular
Thread Starter
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Post

thanks guys, but yes I have IP forwarding enabled & nics are correct with only 1 gateway

I asked for the new router config from the ISP, old config had static routes etc.....

cheers

shunty
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
StefanW
Subaru Parts
4
21 October 2015 09:04 PM
Benrowe727
ScoobyNet General
7
28 September 2015 07:05 AM
nowellyboy
General Technical
0
22 September 2015 02:12 PM
Matt_182
Suspension
6
18 September 2015 05:31 PM
averyp2
ScoobyNet General
3
09 September 2015 03:59 PM



Quick Reply: Urgent - NT 4 Routing



All times are GMT +1. The time now is 08:17 AM.