nv-l

Re: [nv-l] CNAT Configuration qustions

2003-01-10 10:35:49
Subject: Re: [nv-l] CNAT Configuration qustions
From: Gareth Holl <gholl AT us.ibm DOT com>
To: jalonso AT soluziona DOT com
Date: Fri, 10 Jan 2003 10:35:49 -0500

Without sitting down and really looking at your environment I'm just going to say that passthru is broke and that you need to call Support for a fix. Feel free to reference my name when you open a problem ticket. The same fix will address CERT advisory issues for the CNAT product.

Also, does having the NetView Server on the same subnet as the CNAT box work for you as this is not the recommended configuration at v1.2. Moving to v2.1 and doing this would be fine. Also passthru works at v2.1 which you might want to consider moving to.

Hope this helps,

Gareth Holl
Staff Software Engineer
gholl AT us.ibm DOT com

IBM Software Group - Tivoli Brand
Research Triangle Park,  North Carolina.



jalonso AT soluziona DOT com

01/10/2003 08:12 AM

       
        To:        nv-l AT lists.tivoli DOT com
        cc:        jnadal AT soluziona DOT com, fvalencia AT soluziona DOT com
        Subject:        [nv-l] CNAT Configuration qustions



Hi all:

CNAT 1.2 running on AIX 4.3

We have the following test environment:

ROUTER 1 (IP 10.104.193.254)
|
|
----------------------------------------------------------------------------------- LAN 10.104.193.0
|                             |
|                             |
|                             10.104.193.249
Netview BOX                   CNAT BOX    (DEFAULT ROUTE to ROUTER 1)
10.104.193.254                      10.104.200.1
(DEFAULT ROUTE to ROUTER 1)         |
                             |
                             |
------------------------------------------------------------------------------------ LAN 10.104.200.0/128
                             |
                             |
                             |
                             |
                       ROUTER 2 (10.104.200.126)
                             |
                       ----------------- (WAN)
                             |
                       ROUTER 3 (10.104.200.190)
                             |
                             |
------------------------------------------------------------------------------------ LAN 10.104.200.128/192 (CLIENT SIDE)
                             |
                             |
                       MANAGED STATION (10.104.200.189) (DEFAULT ROUTE to ROUTER 3)

Using the following translation rule:

10.104.201.128 10.104.200.128 255.255.255.192 F F 0

we traslate the managed station IP to 10.104.201.189. We also get the payload translated. OK!



if we test the following translation rule, we find the same results:

10.104.201.128 10.104.200.128 255.255.255.192 T F 0

Why is the payload traslated, if we have enabled the Passthru FLAG?




Finallly, we would like to know which translations rules are necessary if we want to
place NAT funcionality on ROUTER 2, and let the CNAT BOX only translate the payload.
Is enough with the following one?:
10.104.201.128 10.104.200.128 255.255.255.192 F F 1


Any help wolud be very appreciated. I can´t find more information than the CNAT manual.

Thanks in advance,

Juan Jose Alonso.-





---------------------------------------------------------------------
To unsubscribe, e-mail: nv-l-unsubscribe AT lists.tivoli DOT com
For additional commands, e-mail: nv-l-help AT lists.tivoli DOT com

*NOTE*
This is not an Offical Tivoli Support forum. If you need immediate
assistance from Tivoli please call the IBM Tivoli Software Group
help line at 1-800-TIVOLI8(848-6548)



<Prev in Thread] Current Thread [Next in Thread>