nv-l

Re: Monitoring a device on the other side of a fire wall

1999-12-02 16:28:23
Subject: Re: Monitoring a device on the other side of a fire wall
From: "Hill, Channing" <CHill AT BBANDT DOT COM>
To: nv-l AT lists.tivoli DOT com
Date: Thu, 2 Dec 1999 16:28:23 -0500
Thanks for the advice James. We currently use numerous scripts to do a
variety of work arounds for ticketing purposes and I guess using one more
won't hurt.

I agree with you Dimitri, but I'm dealing with 2 different groups, Network
Support, who wants to insure that the router in question stays up and
Information Security, who administers all the FW's on the network and can't
really explain why they won't allow ICMP packets to pass. We currently
monitor approximately 3500 nodes with no problems except for the few that
have recently been requested to be seen on the other side of a particular
fire wall.

Thanks
Channing
BB&T Enterprise Management

> -----Original Message-----
> From: Dimitri Setti [SMTP:Dimitri.Setti AT FCCRT DOT IT]
> Sent: Thursday, December 02, 1999 12:06 PM
> To:   NV-L AT UCSBVM.ucsb DOT edu
> Subject:      Re: Monitoring a device on the other side of a fire wall
>
> Hi Hill,
> it's very strange that you permit telnet and ftp from NMS to router and
> you
> don't
> want permit ping!
> In my network, my NMS can ping and use snmp to all routers,  in other side
> of FW
> too,
> but from router to NMS only snmp and tftp is enable on  FW.
>
> bye
>
> Dimitri
>
> "Hill, Channing" <CHill AT BBANDT DOT COM> on 02/12/99 17.47.53
>
> Please respond to Discussion of IBM NetView and POLYCENTER Manager on
> NetView
>       <NV-L AT UCSBVM.UCSB DOT EDU>
>
> To:   NV-L AT UCSBVM.UCSB DOT EDU
> cc:    (bcc: Dimitri Setti/fc0105/fccrt)
>
> Subject:  Monitoring a device on the other side of a fire wall
>
> Hello
>
> Our network support group has requested that Netview (Netview 5.1.1 w/
> Optivity 8.1on AIX 4.2.1) monitor a router that resides on the other side
> of
> a fire wall. Our Information Security Group has configured the fire wall
> to
> allow our NMS station to see the router via snmp requests, telnet, and
> ftp.
> The only problem is that I can't ping the router in order for Netview to
> discover it. I beleive they have a problem with allowing ICMP packets pass
> through the fire wall.
>
> My question is, what other options do we have to monitor this router using
> Netview with the fire wall being in the way
>
> Channing Hill
> BB&T
> Enterprise Management


<Prev in Thread] Current Thread [Next in Thread>