GroupBrowser  




Go Back   GroupBrowser > Novell Newsgroups > Border Manager > Border Manager Network Address Translation
User Name
Password
 
 
Thread Tools Search this Thread Display Modes

Eliminating Public Interface
Old 05-20-2008, 11:26 PM #1
jrost
Guest
 
Status:
Posts: n/a
Default Eliminating Public Interface


I currently have a BM server that host primarily File sharing and
groupwise. I have BM installed on the server and we access groupwise
webaccess, SMTP, IMAP and POP via the public interface. I want to
eliminate the public interface and route all traffic through our 3rd
party firewall and take this server off of the internet. However when I
disable the public interface and change the default route none of the
services are working. I have narrowed it down to the tcpip filters.
What is the best practice for eliminating this interface and making
sure all traffic routes through the private interface. I do not have
any of the BM modules loaded and really dont use any of the services
but I think what happens is traffic comes in through the private but it
is still trying to route through the public interface.


--
jrost
------------------------------------------------------------------------
jrost's Profile: http://forums.novell.com/member.php?userid=18470
View this thread: http://forums.novell.com/showthread.php?t=329332

  Reply With Quote

Re: Eliminating Public Interface
Old 05-27-2008, 05:18 PM #2
Automatic Reply
Guest
 
Status:
Posts: n/a
Default Re: Eliminating Public Interface

jrost,

It appears that in the past few days you have not received a response to your
posting. That concerns us, and has triggered this automated reply.

Has your problem been resolved? If not, you might try one of the following options:

- Visit http://support.novell.com and search the knowledgebase and/or check all
the other self support options and support programs available.
- You could also try posting your message again. Make sure it is posted in the
correct newsgroup. (http://forums.novell.com)

Be sure to read the forum FAQ about what to expect in the way of responses:
http://support.novell.com/forums/faq_general.html

If this is a reply to a duplicate posting, please ignore and accept our apologies
and rest assured we will issue a stern reprimand to our posting bot.

Good luck!

Your Novell Product Support Forums Team
http://support.novell.com/forums/

  Reply With Quote

Re: Eliminating Public Interface
Old 05-27-2008, 07:16 PM #3
Craig Johnson
Guest
 
Status:
Posts: n/a
Default Re: Eliminating Public Interface

This may sound simplistic when you read it, but it really is this
simple. The public interface only gets involved when traffic is sent
to or through it.

Filters are supposed to be applied to the public interface, and not the
private side (unless you've *really* customized them). See tip #13 at
the URL below. (Talking filters here, not exceptions).

If you have changed the default route to an address on the private
side, then packets going to the internet should not touch the public
interface at all. Since you are having a filtering issue, clearly some
things need to be checked out.

1. In filtcfg, check that no filters are applied to the private
interface, and that the filtering action is the default (deny in list,
as seen in tip #13).

2. Check routing table in TCPCON to see what the default route actually
is. Sometimes it's not what you thought you had.

3. Check routers in your network to see if some static NAT or routing
table entry might be pointing to an old public address assigned on the
BMgr server.

4. Use set tcp ip debug=1 (careful! Will see a lot of traffic, and
could crash a production server) to see all IP traffic on the server.
You can then observe packets hitting the public side and maybe see
where they are coming from. PKTSCAN.NLM would be a lot safer to use.


Craig Johnson
Novell Support Connection SysOp
*** For a current patch list, tips, handy files and books on
BorderManager, go to http://www.craigjconsulting.com ***


  Reply With Quote
 


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes





Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Forum Jump




Adobe Newsgroups | Software Newsgroups


Powered by: vBulletin Version 3.0.7
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© 2003-2004 All Rights Reserved GroupBrowser LLC.