GroupBrowser  




Go Back   GroupBrowser > Novell Newsgroups > Border Manager > Border Manager Packet Filtering
User Name
Password
 
 
Thread Tools Search this Thread Display Modes

Problem with TCP/IP static routes
Old 07-09-2008, 05:01 PM #1
Jim Wagner
Guest
 
Status:
Posts: n/a
Default Problem with TCP/IP static routes

This time I do need help. It isn't strictly about packet filtering, and
so if someone can recommend a more appropriate group I'll move my
question there.

I'm trying to "blackhole" certain networks with static routes in
inetcfg. I'm having no problems with networks with masks of
255.255.255.0. The routes for networks with masks of 255.255.0.0 don't
work, however.

Example: I entered static routes for networks of the form a.b.0.0 and
a.c.0.0, each with masks of 255.255.0.0. The routes are passive and the
metrics are 1. For each the destination is 10.0.x.y, which is an unused
but legitimate address on our private network. After entering the
routes and "reinitialize system" I am still able to ping IPs in those
networks. Again, route rules of the form p.q.r.0/255.255.255.0 work
just fine.

Any ideas why these routes are not working?


Jim Wagner
  Reply With Quote

Re: Problem with TCP/IP static routes
Old 07-11-2008, 06:42 PM #2
Craig Johnson
Guest
 
Status:
Posts: n/a
Default Re: Problem with TCP/IP static routes

Are the addresses supernetted?

Craig Johnson
Novell Support Connection SysOp
*** For a current patch list, tips, handy files and books on
BorderManager, go to http://www.craigjconsulting.com ***


  Reply With Quote

Re: Problem with TCP/IP static routes
Old 07-11-2008, 08:30 PM #3
Jim Wagner
Guest
 
Status:
Posts: n/a
Default Re: Problem with TCP/IP static routes

Craig Johnson wrote:
> Are the addresses supernetted?
>
> Craig Johnson



I'm sorry, but could you rephrase the question a bit more concretely? I
rarely deal with network routing, and I'm afraid that "supernetted" is
outside of my lexicon and understanding.


Jim Wagner
  Reply With Quote

Re: Problem with TCP/IP static routes
Old 07-11-2008, 09:07 PM #4
Massimo Rosen
Guest
 
Status:
Posts: n/a
Default Re: Problem with TCP/IP static routes

Hi,

Jim Wagner wrote:
>
> Any ideas why these routes are not working?


What does tcpcon say about these routes

CU,
--
Massimo Rosen
Novell Product Support Forum Sysop
No emails please!
http://www.cfc-it.de
  Reply With Quote

Re: Problem with TCP/IP static routes
Old 07-14-2008, 11:01 AM #5
Jim Wagner
Guest
 
Status:
Posts: n/a
Default Re: Problem with TCP/IP static routes

Massimo Rosen wrote:
> Hi,
>
> Jim Wagner wrote:
>> Any ideas why these routes are not working?

>
> What does tcpcon say about these routes
>
> CU,


It doesn't list those two broken class-B routes at all. It does,
however, list some routes for class-C networks that I created. I assume
this means I have something configured improperly.


Jim Wagner
  Reply With Quote

Re: Problem with TCP/IP static routes
Old 07-14-2008, 01:41 PM #6
Massimo Rosen
Guest
 
Status:
Posts: n/a
Default Re: Problem with TCP/IP static routes

Hi,

Jim Wagner wrote:
>
> Massimo Rosen wrote:
> > Hi,
> >
> > Jim Wagner wrote:
> >> Any ideas why these routes are not working?

> >
> > What does tcpcon say about these routes
> >
> > CU,

>
> It doesn't list those two broken class-B routes at all.


Weird.

Can you post sys:\etc\gateways?

CU,
--
Massimo Rosen
Novell Product Support Forum Sysop
No emails please!
http://www.cfc-it.de
  Reply With Quote

Re: Problem with TCP/IP static routes
Old 07-14-2008, 03:12 PM #7
Jim Wagner
Guest
 
Status:
Posts: n/a
Default Re: Problem with TCP/IP static routes

Massimo Rosen wrote:
> Can you post sys:\etc\gateways?


Gladly, although with some obfuscation for security reasons. All of the
class-C routes work, but the class-B's do not.


Net 0 Gateway w.x.y.254 Metric 1 Passive
Net m.n.8.0/255.255.255.0 Gateway 10.0.q.r Metric 1 Passive
Net m.n.9.0/255.255.255.0 Gateway 10.0.q.r Metric 1 Passive
Net m.n.10.0/255.255.255.0 Gateway 10.0.q.r Metric 1 Passive
Net m.n.11.0/255.255.255.0 Gateway 10.0.q.r Metric 1 Passive
Net a.b.0.0/255.255.0.0 Gateway 10.0.q.r Metric 1 Passive
Net a.c.0.0/255.255.0.0 Gateway 10.0.q.r Metric 1 Passive
Net a.c.1.0/255.255.255.0 Gateway 10.0.q.r Metric 1 Passive


Jim Wagner
  Reply With Quote

Re: Problem with TCP/IP static routes
Old 07-17-2008, 09:58 PM #8
Craig Johnson
Guest
 
Status:
Posts: n/a
Default Re: Problem with TCP/IP static routes

Supernetting means to take (as one example) a class C address and give
it a class B subnet mask.

For instance, you try to set something up like this:
192.168.0.0 (255.255.0.0)

That's a class C network address with class B mask, and is thus
supernetted.

NetWare will allow this as an end node, but not as a router. Filters
will not work if supernetted either.

Craig Johnson
Novell Support Connection SysOp
*** For a current patch list, tips, handy files and books on
BorderManager, go to http://www.craigjconsulting.com ***


  Reply With Quote

Re: Problem with TCP/IP static routes
Old 07-18-2008, 06:29 AM #9
Massimo Rosen
Guest
 
Status:
Posts: n/a
Default Re: Problem with TCP/IP static routes

Craig,

Craig Johnson wrote:
>
> Supernetting means to take (as one example) a class C address and give
> it a class B subnet mask.
>
> For instance, you try to set something up like this:
> 192.168.0.0 (255.255.0.0)
>
> That's a class C network address with class B mask, and is thus
> supernetted.
>
> NetWare will allow this as an end node, but not as a router. Filters
> will not work if supernetted either.


All true, but of course there's no problem whatsoever to define whatever
routes you like. Supernetting problems only apply when the local IP of
the server comes into play, but that's not the issue here.

CU,
--
Massimo Rosen
Novell Product Support Forum Sysop
No emails please!
http://www.cfc-it.de
  Reply With Quote

Re: Problem with TCP/IP static routes
Old 08-27-2008, 10:46 PM #10
Casino Canberra Helpdesk
Guest
 
Status:
Posts: n/a
Default Re: Problem with TCP/IP static routes


Jim Wagner;1597183 Wrote:
> Massimo Rosen wrote:
> > Can you post sys:\etc\gateways?

>
> Gladly, although with some obfuscation for security reasons. All of
> the
> class-C routes work, but the class-B's do not.
>
>
> Net 0 Gateway w.x.y.254 Metric 1 Passive
> Net m.n.8.0/255.255.255.0 Gateway 10.0.q.r Metric 1 Passive
> Net m.n.9.0/255.255.255.0 Gateway 10.0.q.r Metric 1 Passive
> Net m.n.10.0/255.255.255.0 Gateway 10.0.q.r Metric 1 Passive
> Net m.n.11.0/255.255.255.0 Gateway 10.0.q.r Metric 1 Passive
> Net a.b.0.0/255.255.0.0 Gateway 10.0.q.r Metric 1 Passive
> Net a.c.0.0/255.255.0.0 Gateway 10.0.q.r Metric 1 Passive
> Net a.c.1.0/255.255.255.0 Gateway 10.0.q.r Metric 1 Passive
>
>
> Jim Wagner


I must ask why you are using inetcfg. If you are using bordermanager
use filtcfg and deny the routes by selecting configure tcp/ip filters |
Outgoing rip filters and incoming rip filters.


--
Casino_Canberra_Helpdesk
------------------------------------------------------------------------
Casino_Canberra_Helpdesk's Profile: http://forums.novell.com/member.php?userid=16101
View this thread: http://forums.novell.com/showthread.php?t=335751

  Reply With Quote
 


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes





Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Forum Jump




Adobe Newsgroups | Software Newsgroups


Powered by: vBulletin Version 3.0.7
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© 2003-2004 All Rights Reserved GroupBrowser LLC.