Re: Possible DNS problem

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Ace Fekay [MVP] (PleaseSubstituteMyActualFirstName&LastNameHere_at_hotmail.com)
Date: 02/15/05


Date: Mon, 14 Feb 2005 23:11:50 -0500

In news:eBKch%23wEFHA.2180@TK2MSFTNGP12.phx.gbl,
Kevin D. Goodknecht Sr. [MVP] <admin@nospam.WFTX.US> made a post then I
commented below
>> U-turns? Interesting way to put it, but accurate! I think
>> you got that from your old trucking days!
>
> You got that right!
>
> Besides, If the firewall is worth its stuff, it would reject the
> packets as spoofed packets, anyway.

I figured it was from your driving days!

Many a firewall we have to state to ignore that range in the rules, such as
a Cisco IOS IP access rules (the way I used to do it). Not sure about the
newer ones, but I would assume it would have to be stated. But that is for
inbound, not inside requests hitting the inside interface for the outside
WAN interface. As for NAT, all NATs don't allow U-Turns, just as a traffic
cop!

Ace



Relevant Pages

  • rv042 one to one nat access rules
    ... Has anyone got one to one nat working w/ access rules with the Linksys ... All traffic flow fine. ... all ports. ...
    (comp.security.firewalls)
  • Re: ISA dial up issue
    ... external interface of the ISA box... ... if there are access rules on the ISA allowing traffic ... case just hit the external IP) there is no NAT or proxying. ...
    (microsoft.public.isa)
  • Re: Fake address for NAT connection support (IPv4)
    ... With my DSL modem the default configuration was to function in NAT ... I can't currently do that with my ISP: ... in and out I /have/ to have on my WAN interface the RFC1918 static ...
    (comp.os.linux.networking)
  • Re: PIX 501 Routing vs. NAT
    ... what are you trying to accomplish? ... You can assign as many IP address to the wan interface, however without NAT, you can not publish any services behind the firewall unless your machines reside on the same subnet as the outside interface, which means you are using no nat rules. ...
    (comp.dcom.sys.cisco)
  • Network Rule
    ... Beside's access rules, in order to access From: Perimeter To: Internal, do I ... need to Setup a Network Rule? ... If so, NAT or ROUTE? ...
    (microsoft.public.isa.enterprise)