Hm ... if you capture the traffic on the ext. segment and see outgoing but no returning packages, are you sure that this is a problem with you FW ?
Maybe the packages are routet back to your old Cluster ???
/M.
you're right, you don't need a return rule.
Routes for you're internal networks on your Internet router should also be ok.
If you run a tcpdump on the ext. FW interface of your primary vrrp box - do you see outgoing packages to your internet router ?
/Martin
Hi FB,
what about your NAT configuration ? How is it configured ?
It seems that your package is accepted and forwarded from the FW to the 'external' devices but this device has no route back.
/Martin
the supported Kernel versions for RH 7.0 are 2.2.16, 2.2.17 and 2.2.19 - my experience with 2.2.19 are that it is very stable. I had no problems with it.
/Martin
hi rasindia
i'm interested in this question too.
In my opinion there isn’t a security problem in using public ip addresses in your DMZ. If your systems in the DMZ protected by strong firewall rules and the latest os security patches, they will be sufficient protected for “normal customers”.
If...
Hi Matts,
We had a similar problem with DSL. It was possible to download files from the internal network to the VPN-client. But when I tried to copy the file back from the client to the internal server it fails.
Then I reduced the MTU-Size on the client PC and after that I could copy files in...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.