Ascend Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: (ASCEND) Remote admin of SAF



         Reply to:   Re: (ASCEND) Remote admin of SAF
Dean Frye wrote:
>Turn on logging on the firewall for trusted sites and see if you get a
>!pass (reject) message for udp port 69. Be careful not to enable logging
>to a syslog server on the other side of the firewall if the firewall
>doesn't allow syslog.

Unfortunately I don't have access to a Unix box to run syslog on :-( Is there another way of checking this?

>Uploading a firewall requires the following:
>- telnet connectivity
>- no other session in debug mode
>- tftp connectivity

I'm sure I have all of these; if not, then I wouldn't be able to upload a firewall locally (ie. through the LAN port). My remote site is trusted, and I can telnet to the P50, so there doesn't seem to be a reason why tftp shouldn't work as well.

There is one complication I forgot to mention; as my ISP is using Cisco, I'm using interface-based routing, so my WAN port has an IP address outside of the subnet of my LAN address. My firewall makes no mention of the WAN port IP address

------------------------
IDEO London User Support ------------------------
mailto:srahilly@ideo.com
P + 44 (0) 1523 132852
D + 44 (0) 171 813 0587 x 2258
http://www.ideoeurope.com
T + 44 (0) 171 485 1170
F + 44 (0) 171 482 3970

++ Ascend Users Mailing List ++
To unsubscribe:	send unsubscribe to ascend-users-request@bungi.com
To get FAQ'd:	<http://www.nealis.net/ascend/faq>


Follow-Ups: