Re: AIX routing

From: John Jolet (john.jolet_at_FXFN.COM)
Date: 04/28/04

  • Next message: Gipson, Mat: "Re: Accidentially Removed a Volume Group"
    Date:         Wed, 28 Apr 2004 10:27:50 -0500
    To: aix-l@Princeton.EDU
    
    

    this sounds like a networking problem external to the rs/6000. if you
    have external users accessing the webserver NOT through the firewall,
    don't you have a rather severe security problem? if traffic comes from,
    say, 10.10.10.1, the networking gear in general should make the decision
    which of the 3 interfaces to route it to. You might need to, in this
    case, get the routing table updates from the routers. Are your routers
    running rip? what routing update protocol is your network gear using?

    Mark Lamport wrote:

    >One interface is a webserver, its registered address is the address at the
    >firewall. At the server it is another address which is resolved locally.
    >Any traffic that comes through the firewall into the
    >server must go back through the firewall. The inside firewall is the
    >default gateway. If a remote user tries to connect via the other 2
    >interfaces, it does not work because the packet is routed through the
    >firewall. If I add a static route for a user coming in the other interfaces,
    >they work but they can't come in to the webserver via the firewall because
    >their packets will be routed by out the interface the static route was setup
    >on. I agree, it appears all routing is done via destination address. I
    >would like to route via destination and source or interface.
    >
    >AIX 5200-02
    >
    >
    >
    >
    >----- Original Message -----
    >From: "John Jolet" <john.jolet@FXFN.COM>
    >Newsgroups: bit.listserv.aix-l
    >To: <aix-l@Princeton.EDU>
    >Sent: Wednesday, April 28, 2004 9:49 AM
    >Subject: Re: AIX routing
    >
    >
    >
    >
    >>what are you trying to accomplish? you can have only one default
    >>route. ALL ip routing on ALL unix variants and all routers is done by
    >>destination ip address. what version of aix?
    >>
    >>Mark Lamport wrote:
    >>
    >>
    >>
    >>>I have a RS/6000 with 3 interfaces, one of which is connected to a
    >>>
    >>>
    >firewall.
    >
    >
    >>>It appears all AIX routing is performed by destination ip address. Is
    >>>
    >>>
    >there
    >
    >
    >>>a way to perform routing by interface? I have tried the smit route but
    >>>appears only to add another entry in the routing table for the
    >>>
    >>>
    >destination
    >
    >
    >>>addess.
    >>>
    >>>thanks.
    >>>
    >>>Mark Lamport
    >>>
    >>>
    >>>
    >>>


  • Next message: Gipson, Mat: "Re: Accidentially Removed a Volume Group"

    Relevant Pages

    • Re: Forwarding not work in FC9 but ip forward is turn on
      ... It's used for default networking when your system is set to DHCP ... Your firewall has the 3 interfaces with 192.168.1.231/24, ... 1).From the firewall, if you ping/traceroute to the 3 off firewall ... 3).On the off firewall machines, what does a tcpdump show about the ...
      (Fedora)
    • Re: Web server behind Symantec Enterprise Firewall
      ... It seems it does not matter wich interfaces i set at the rule, ... tries to route it trought the same interface. ... firewall to the internal sever?... ... > on the firewall to point to the web server. ...
      (comp.security.firewalls)
    • Re: Fw: Serious Security Issue in Windows XP SP2s Firewall
      ... This applies to all interfaces. ... >> unreachable, and it was a domain member, and you then installed SP2, the ... > different policy to override this. ... >> not have NB filtered by the firewall. ...
      (Focus-Microsoft)
    • Re: router and adsl?
      ... Most firewall vendors have boxes with 3 interfaces. ... choice if you have a limited budget and arenīt too paranoid. ... >> network, but not with the other company. ...
      (microsoft.public.win2000.security)
    • Re: Lan to Wan reprise
      ... the machines on the Lan can't get past the firewall. ... #if you're a router (and thus should forward IP packets between interfaces), ... iptables -P INPUT DROP ...
      (Fedora)