Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Nokia routing problem

Status
Not open for further replies.

tabularasa

Technical User
Sep 20, 2002
65
US
Ok, i think i have the problem isolated.

I have a nokia 530 with 4 interfaces.

4 interfaces

10.10.0.0/24 LAN
63.x.x.x WAN1
65.x.x.x WAN2
10.10.1.0/24 DMZ

The 530 can go anywhere. Can ping, tracert, nslookup anything.

however, from behind the LAN segment no TCP connections can be formed. I can ping yahoo, i can nslookup yahoo, though i can not get to yahoo.

i have the default route set up to the 65.x.x.x router.

i can traceroute to IP addresses on the 65 subnet, but no further. IE, tracert yahoo.com :

10ms 10.10.0.240
* * * *
* * * *

i can ping the DNS servers, but not tracert to them.

Thanks in advance! Help!!
 
What address is the trace coming from? Is is another LAN segment separate from the 10.10.0.0 /24 LAN or is the trace coming from a machine on that LAN?

Your trace seems to hit the firewall so I would presume that you would be getting a log entry if the firewall is dropping the traffic. Have you checked the logs?

Chris.
**********************
Chris Andrew, CCNA, CCSA
chris@iproute.co.uk
**********************
 
if you are using a windows tracert then the problem lies with checkpoint.
i know of no-one who has managed to get a windows tracert successfuly through the firewall. this was a topic discussed on phoneboys site for a while with no resolution. it seems to be a quirk of NG
 
You guys are the best. Thanks for the quick responses.

The trace is coming from 10.10.0.110. i can trace succesfully through the firewall to the router. IE: 10.10.0.110 ---> 10.10.0.240 ---> 65.x.x.x

though if i try to go anywhere else i can not. I can not get on the internet. I can ping yahoo.com, i can NSlookup yahoo, but i can not get there.

All of this is before i push the policy. I did a fw unloadlocal before i did all of this. So, i know its a nokia issue. So when i try to hit a web page, it resolves DNS, then stops. In the log it shows that it accepts domain from the firewall to the name server.

When i did push the policy to see if there was a NAT issue,
In the log it shows nothing out of the ordinary. It denies something to the router on 63.x.x.x, which explains why i cant ping it. (but thats a whole other issue) and it shows being denied trying to get to microsoft and aol.

Send me you emails and i will send you the log.

thanks!

Ryan
 
i wont be back on until monday but if you send the log to alltsec@yahoo.co.uk

is it possible to see a screenshot of the policy? and the translation policy
 
Piloria,

The policy is uninstalled. Does that mean the NAT is also not installed?

 
if no policy is installed i beleve that also means nat is not installed

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top