Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Network Security: Firewall, NAT, QoS, IPS and more

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-26-2008, 05:46 PM
Junior Member
 
Join Date: Mar 2002
Posts: 24
Angry Policy Routing Help Please

Hi All

I am trying to move over from ASL 6.x to 7.x and have problem
On the 6.x box the "addtional addresses on an interface" were still "interfaces" on v7.x they are not selectable as interfaces. this is a problem (I think)

I had on the 6.x box a policy route which had an "additional address on an interface" as the source interface but in V7.x you cannot select the "additional address on an interface" as a source.

I do not know wether I'm being stupid or not but can anyone help ?
__________________
Never underestimate the predictability of stupidity
Reply With Quote
  #2 (permalink)  
Old 06-27-2008, 12:51 PM
AMros's Avatar
Senior Member
 
Join Date: Jan 2003
Location: Berlin/Germany
Posts: 308
Default

ignore the source ifc and user the add. ifc related network as source network?
a.
Reply With Quote
  #3 (permalink)  
Old 06-09-2009, 07:27 PM
Junior Member
 
Join Date: Mar 2002
Posts: 24
Angry

Hi This problem has reared its ugly head again !!

I cannot do that as I need to route from the internet

any ideas ?
__________________
Never underestimate the predictability of stupidity
Reply With Quote
  #4 (permalink)  
Old 06-09-2009, 08:26 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,391
Default

Silver, what version of Astaro? Can you also provide some perpective on the problem you need to solve - I mean, what is the reason you "need to route from the internet?"

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #5 (permalink)  
Old 06-09-2009, 09:56 PM
Junior Member
 
Join Date: Mar 2002
Posts: 24
Default

Hi Bob Thanks for the interest

I have two routers that conect to the internet, one ADSL and one SDSL both have 8 puplic IPs (/29)

The ADSL router (IP xx.xx.xx.102/29) is the default GW and is used for web browsing downloads etc (the interface on the ASL box is xx.97)

The SDSL router (IP yy.yy.yy.33/29) carries our VPNs these are policy routed to the SDSL router and out on yy.34 this works fine (the interface on the ASL box is yy.34)

What I need to do is allow an incoming to yy.35 and pass it to a host on our internal network and route it via yy.33 and back out on yy.35 (its a polycom videoconferencing device)

In ASL v 6.xx I had yy.35 as an additional address on yy.34 and policy routed in and out of the ASL box (see attachment) but in V7.xx you cannot policy route to an additional address

I am (Trying to use) using ASL 7.403


Any Help would be great

Thanks
Jeff
Attached Images
File Type: jpg Policy Route 2.JPG (63.1 KB, 13 views)
__________________
Never underestimate the predictability of stupidity
Reply With Quote
  #6 (permalink)  
Old 06-10-2009, 03:21 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,391
Default

It's been awhile since I've thought about V6, but I guess that you can achieve the same thing by selecting a 'Route type' of "Gateway route" in V7.

Does anyone know if he could solve his Polycom problem better with the H.323 support?
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #7 (permalink)  
Old 06-10-2009, 10:15 PM
Junior Member
 
Join Date: Mar 2002
Posts: 24
Default

Hi Bob

Yeah that what I figured but you cannot policy route from an "addtional address on interface" in V 7.xx IE you cannot define a "Source Interface"

You can with V6

Jeff
__________________
Never underestimate the predictability of stupidity
Reply With Quote
  #8 (permalink)  
Old 06-11-2009, 01:13 AM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,391
Default

Barry could give you a better answer when it comes to creating policy routes.

In general, I would use DNAT/SNAT to resolve issues like yours where a single internal IP needs to appear to the outside on an Additional Address on an external interface.

For example, for inbound traffic initiated from the outside:
Traffic Source: Any
Traffic Service: [group of services involved or 'Any']
Traffic Destination: [yy.yy.yy.35]

NAT mode: DNAT (Destination)

Destination: [internal IP of Polycom device]
Destination Service: [leave empty]
And, for outbound traffic initiated from inside:
Traffic Source: [internal IP of Polycom device]
Traffic Service: [group of services involved or 'Any']
Traffic Destination: Any

NAT mode: SNAT (Source)

Source: [yy.yy.yy.35]
Source Service: [leave empty]

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #9 (permalink)  
Old 06-11-2009, 09:00 AM
Junior Member
 
Join Date: Mar 2002
Posts: 24
Default

Hi Bob

I need to do NAT and Policy routing !

As I said I have this working fine on V6

The interface yy is not on the default gateway device

The policy route creates a gateway for interface yy

Jeff
__________________
Never underestimate the predictability of stupidity
Reply With Quote
  #10 (permalink)  
Old 06-11-2009, 11:37 AM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 5,391
Default

You mean changing the default gateway in the Polycom doesn't resolve the need for a route?
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:58 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.