Routing with Netra X1 (Solaris 8)

From: Andreas Hoeschler (ahoesch@smartsoft.de)
Date: Mon Feb 17 2003 - 09:57:05 EST


Dear managers,

I have got no answers for my question (Netra refuses to let in traffic
from the internet) . I assume this is because it seems I have done
everything right and nobody has a clue why it does not work. I am close
to reinstall the whole OS and give it a second try. However, this is a
bit unsatifactiory. If anyone has a clue, please let me know. I have
attached the origial question (will summarize).

Regards,

    Andreas

====================================================================
We have been given a subnet of 8 public IP adresses by our provider. I
am trying to setup a Netra to work as a router/firewall between the
internet (public subnet) and our internal network (192.168.1.0). The
public network is described as follows:

212.108.168.48 network
212.108.168.49 router
212.108.168.50 Netra X1
255.255.255.248 netmask

The interface dmfe1 is connected to the ISPs switch. A notebook is
connected to the internal interface dmfe0 to simulate the internal
network. On the Netra I get the following:

bash-2.03# ndd -get /dev/ip ip_forwarding
1
bash-2.03# netstat -rn

Routing Table: IPv4
   Destination Gateway Flags Ref Use Interface
-------------------- -------------------- ----- ----- ------ ---------
212.108.168.48 212.108.168.50 U 1 23 dmfe1
192.168.1.0 192.168.1.1 U 1 31 dmfe0
224.0.0.0 192.168.1.1 U 1 0 dmfe0
default 212.108.168.49 UG 1 44
127.0.0.1 127.0.0.1 UH 8 40162 lo0

I can successfully reach any internet address from the Netra. I can log
into the Netra with telnet, ssh,... from the Notebook in the internal
network over dmfe0. I can log into the Netra over dmfe1 from a machine
in the public subnet 212.108.168.48 e.g. from a machine with the address
212.108.168.51. However, I cannot reach the machine from the internet.
An attempt to log into the Netra using ssh produces a timeout.

bash2.05 ahoesch@localhost ~ % ssh 212.108.168.50
ssh: connect to address 212.108.168.50 port 22: Operation timed out

Any clues? Thanks a lot for any advice!

Regards,

   Andreas

PS: The provider seems to have setup the public subnet right since I
notebook connected to the ISPs switch and configured as 212.108.168.50
works great and is reachable from the outside.
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:25:49 EDT