[prev in list] [next in list] [prev in thread] [next in thread]
List: loadbalancing-l
Subject: RE: [load balancing] managing Alteons from several networks
From: "Peter Degrassi" <degrassi () nortelnetworks ! com>
Date: 2002-05-27 21:06:18
[Download RAW message or body]
Hi Arie,
I am not entirely clear on why you cannot use a filters to control access on
the incoming port. Please fully explain your topology and configuration.
We can take this off-line if you prefer not to divulge this information to
the list.
Regards... Peter
-----Original Message-----
From: Arie Vayner [mailto:ariev@netvision.net.il]
Sent: Monday, May 27, 2002 5:31 PM
To: lb-l@vegan.net; lb-l@vegan.net
Subject: RE: [load balancing] managing Alteons from several networks
Still, filters per vlan, or using another port for managment does not solve
the problem, because I can put filters on the new port, and that is fine,
BUT, an intruder can still access the ip interface of the main port, where I
am unable to put a filter because of the symetric redirection features...
Any ideas?
Arie
-----Original Message-----
From: Peter Degrassi [mailto:degrassi@nortelnetworks.com]
Sent: ב 27/05/2002 15:22
To: 'lb-l@vegan.net'
Cc:
Subject: RE: [load balancing] managing Alteons from several networks
Hi Arie,
Filters per VLAN are supported with the AD4/184 and WebOS 10.0.
Peter
-----Original Message-----
From: Arie Vayner [mailto:ariev@netvision.net.il]
Sent: Monday, May 27, 2002 3:49 AM
To: lb-l@vegan.net
Subject: RE: [load balancing] managing Alteons from several
networks
I tried using the taged trunk, so I would have a vlan for
normal traffic, and a vlan for managment.
The problem is that I cannot specify a filter per vlan... it
is not like a Cisco router, where you have sub-interfaces...
as it seems I will have to waste a port for managment
Arie
-----Original Message-----
From: claudio rosa [mailto:crmrosa@terra.com.br]
Sent: Monday, May 27, 2002 12:35 AM
To: lb-l@vegan.net
Subject: RES: [load balancing] managing Alteons from
several networks
Hi Arie,
You can try many differents things. You can try to
do a NAT to the
management workstation, a SNMP proxy, as Chris told,
a filter with a number
lower or if you have a empty port you work with a
filter in this port(may be
with a another interface/vlan)), ok?
Rgds,
Cláudio Rosa
-----Mensagem original-----
De: owner-lb-l@vegan.net
[mailto:owner-lb-l@vegan.net]Em nome de Arie
Vayner
Enviada em: domingo, 26 de maio de 2002 04:21
Para: lb-l@vegan.net
Assunto: [load balancing] managing Alteons from
several networks
Hi
How can I manage an Alteon box securly, while having
a few management hosts,
located on different networks?
I have been using the management network feature,
but the need has arised to
have another host running SNMP to the Alteon, and
this host is located on a
different part of my network, so managmenet network
is not working for me.
Also, I cannot run a filter on the main feed port
because I am running
traffic redirection to a proxy, and it does not
allow to activate a filter
on this port.
We are running version 9 something.
Any ideas?
Arie
____________________
The Load Balancing Mailing List
Unsubscribe:
mailto:majordomo@vegan.net?body=unsubscribe%20lb-l
Archive: http://vegan.net/lb/archive
LBDigest: http://lbdigest.com
MRTG with SLB: http://vegan.net/MRTG
Hosted by: http://www.tokkisystems.com
____________________
The Load Balancing Mailing List
Unsubscribe:
mailto:majordomo@vegan.net?body=unsubscribe%20lb-l
Archive: http://vegan.net/lb/archive
LBDigest: http://lbdigest.com
MRTG with SLB: http://vegan.net/MRTG
Hosted by: http://www.tokkisystems.com
____________________
The Load Balancing Mailing List
Unsubscribe: mailto:majordomo@vegan.net?body=unsubscribe%20lb-l
Archive: http://vegan.net/lb/archive
LBDigest: http://lbdigest.com
MRTG with SLB: http://vegan.net/MRTG
Hosted by: http://www.tokkisystems.com
[Attachment #3 (text/html)]
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=utf-8">
<META NAME="Generator" CONTENT="MS Exchange Server version 5.5.2655.35">
<TITLE>RE: [load balancing] managing Alteons from several networks</TITLE>
</HEAD>
<BODY>
<P><FONT SIZE=2>Hi Arie,</FONT>
</P>
<P><FONT SIZE=2>I am not entirely clear on why you cannot use a filters to control \
access on the incoming port. Please fully explain your topology and \
configuration. We can take this off-line if you prefer not to divulge this \
information to the list.</FONT></P>
<P><FONT SIZE=2>Regards... Peter</FONT>
</P>
<P><FONT SIZE=2>-----Original Message-----</FONT>
<BR><FONT SIZE=2>From: Arie Vayner [<A \
HREF="mailto:ariev@netvision.net.il">mailto:ariev@netvision.net.il</A>]</FONT> \
<BR><FONT SIZE=2>Sent: Monday, May 27, 2002 5:31 PM</FONT> <BR><FONT SIZE=2>To: \
lb-l@vegan.net; lb-l@vegan.net</FONT> <BR><FONT SIZE=2>Subject: RE: [load balancing] \
managing Alteons from several networks</FONT> </P>
<BR>
<P><FONT SIZE=2>Still, filters per vlan, or using another port for managment does not \
solve the problem, because I can put filters on the new port, and that is fine, BUT, \
an intruder can still access the ip interface of the main port, where I am unable to \
put a filter because of the symetric redirection features...</FONT></P>
<P><FONT SIZE=2> </FONT>
<BR><FONT SIZE=2>Any ideas?</FONT>
<BR><FONT SIZE=2> </FONT>
<BR><FONT SIZE=2>Arie</FONT>
</P>
<P> <FONT SIZE=2>-----Original Message----- \
</FONT> <BR> <FONT SIZE=2>From: Peter \
Degrassi [<A HREF="mailto:degrassi@nortelnetworks.com">mailto:degrassi@nortelnetworks.com</A>] \
</FONT> <BR> <FONT SIZE=2>Sent: ב \
27/05/2002 15:22 </FONT> <BR> <FONT \
SIZE=2>To: 'lb-l@vegan.net' </FONT> <BR> \
<FONT SIZE=2>Cc: </FONT> <BR> <FONT \
SIZE=2>Subject: RE: [load balancing] managing Alteons from several networks</FONT> \
<BR> \
<BR> \
<BR> <FONT SIZE=2>Hi Arie,</FONT> \
<BR> <FONT SIZE=2> </FONT> \
<BR> <FONT SIZE=2>Filters per VLAN are \
supported with the AD4/184 and WebOS 10.0.</FONT> \
<BR> <FONT SIZE=2> </FONT> \
<BR> <FONT SIZE=2>Peter</FONT> </P>
<P> \
<FONT SIZE=2>-----Original \
Message-----</FONT> <BR> \
<FONT SIZE=2>From: Arie Vayner [<A \
HREF="mailto:ariev@netvision.net.il">mailto:ariev@netvision.net.il</A>]</FONT> \
<BR> \
<FONT SIZE=2>Sent: Monday, May 27, 2002 \
3:49 AM</FONT> <BR> \
<FONT SIZE=2>To: lb-l@vegan.net</FONT> \
<BR> \
<FONT SIZE=2>Subject: RE: [load balancing] \
managing Alteons from several networks</FONT> \
<BR> \
\
<BR> \
\
<BR> \
<FONT SIZE=2>I tried using the taged \
trunk, so I would have a vlan for normal traffic, and a vlan for managment.</FONT> \
<BR> \
<FONT SIZE=2>The problem is that I cannot \
specify a filter per vlan... it is not like a Cisco router, where you have \
sub-interfaces...</FONT></P>
<P> \
<FONT SIZE=2> </FONT> \
<BR> \
<FONT SIZE=2>as it seems I will have to \
waste a port for managment</FONT> <BR> \
<FONT SIZE=2> </FONT> \
<BR> \
<FONT SIZE=2>Arie</FONT> </P>
<P> \
\
<FONT SIZE=2>-----Original Message-----</FONT> \
<BR> \
\
<FONT SIZE=2>From: claudio rosa [<A \
HREF="mailto:crmrosa@terra.com.br">mailto:crmrosa@terra.com.br</A>] </FONT> \
<BR> \
\
<FONT SIZE=2>Sent: Monday, May 27, 2002 12:35 AM</FONT> \
<BR> \
\
<FONT SIZE=2>To: lb-l@vegan.net</FONT> <BR> \
\
<FONT SIZE=2>Subject: RES: [load balancing] managing Alteons from several \
networks</FONT> <BR> \
\
<BR> \
\
</P>
<P> \
\
<FONT SIZE=2>Hi Arie, </FONT> </P>
<P> \
\
<FONT SIZE=2>You can try many differents things. You can try to do a NAT to the \
</FONT> <BR> \
\
<FONT SIZE=2>management workstation, a SNMP proxy, as Chris told, a filter with a \
number </FONT> <BR> \
\
<FONT SIZE=2>lower or if you have a empty port you work with a filter in this \
port(may be </FONT> <BR> \
\
<FONT SIZE=2>with a another interface/vlan)), ok? </FONT> </P>
<P> \
\
<FONT SIZE=2>Rgds, </FONT> </P>
<P> \
\
<FONT SIZE=2>Cláudio Rosa </FONT> </P>
<P> \
\
<FONT SIZE=2>-----Mensagem original----- </FONT> \
<BR> \
\
<FONT SIZE=2>De: owner-lb-l@vegan.net [<A \
HREF="mailto:owner-lb-l@vegan.net">mailto:owner-lb-l@vegan.net</A>]Em nome de Arie \
</FONT> <BR> \
\
<FONT SIZE=2>Vayner </FONT> <BR> \
\
<FONT SIZE=2>Enviada em: domingo, 26 de maio de 2002 04:21 </FONT> \
<BR> \
\
<FONT SIZE=2>Para: lb-l@vegan.net </FONT> \
<BR> \
\
<FONT SIZE=2>Assunto: [load balancing] managing Alteons from several networks </FONT> \
</P> <BR>
<P> \
\
<FONT SIZE=2>Hi </FONT> </P>
<P> \
\
<FONT SIZE=2>How can I manage an Alteon box securly, while having a few management \
hosts, </FONT> <BR> \
\
<FONT SIZE=2>located on different networks? </FONT> \
<BR> \
\
<FONT SIZE=2>I have been using the management network feature, but the need has \
arised to </FONT> <BR> \
\
<FONT SIZE=2>have another host running SNMP to the Alteon, and this host is located \
on a </FONT> <BR> \
\
<FONT SIZE=2>different part of my network, so managmenet network is not working for \
me. </FONT> </P>
<P> \
\
<FONT SIZE=2>Also, I cannot run a filter on the main feed port because I am running \
</FONT> <BR> \
\
<FONT SIZE=2>traffic redirection to a proxy, and it does not allow to activate a \
filter </FONT> <BR> \
\
<FONT SIZE=2>on this port. </FONT> </P>
<P> \
\
<FONT SIZE=2>We are running version 9 something. </FONT> </P>
<P> \
\
<FONT SIZE=2>Any ideas? </FONT> </P>
<P> \
\
<FONT SIZE=2>Arie </FONT> <BR> \
\
<FONT SIZE=2>____________________ </FONT> \
<BR> \
\
<FONT SIZE=2>The Load Balancing Mailing List </FONT> \
<BR> \
\
<FONT SIZE=2>Unsubscribe: <A \
HREF="mailto:majordomo@vegan.net?body=unsubscribe%20lb-l">mailto:majordomo@vegan.net?body=unsubscribe%20lb-l</A> \
</FONT> <BR> \
\
<FONT SIZE=2>Archive: <A \
HREF="http://vegan.net/lb/archive" TARGET="_blank">http://vegan.net/lb/archive</A> \
</FONT> <BR> \
\
<FONT SIZE=2>LBDigest: <A \
HREF="http://lbdigest.com" TARGET="_blank">http://lbdigest.com</A> </FONT> \
<BR> \
\
<FONT SIZE=2>MRTG with SLB: <A HREF="http://vegan.net/MRTG" \
TARGET="_blank">http://vegan.net/MRTG</A> </FONT> \
<BR> \
\
<FONT SIZE=2>Hosted by: <A \
HREF="http://www.tokkisystems.com" TARGET="_blank">http://www.tokkisystems.com</A> \
</FONT> </P>
<BR>
<BR>
<P> \
\
<FONT SIZE=2>____________________ </FONT> \
<BR> \
\
<FONT SIZE=2>The Load Balancing Mailing List </FONT> \
<BR> \
\
<FONT SIZE=2>Unsubscribe: <A \
HREF="mailto:majordomo@vegan.net?body=unsubscribe%20lb-l">mailto:majordomo@vegan.net?body=unsubscribe%20lb-l</A> \
</FONT> <BR> \
\
<FONT SIZE=2>Archive: <A \
HREF="http://vegan.net/lb/archive" TARGET="_blank">http://vegan.net/lb/archive</A> \
</FONT> <BR> \
\
<FONT SIZE=2>LBDigest: <A \
HREF="http://lbdigest.com" TARGET="_blank">http://lbdigest.com</A> </FONT> \
<BR> \
\
<FONT SIZE=2>MRTG with SLB: <A HREF="http://vegan.net/MRTG" \
TARGET="_blank">http://vegan.net/MRTG</A> </FONT> \
<BR> \
\
<FONT SIZE=2>Hosted by: <A \
HREF="http://www.tokkisystems.com" TARGET="_blank">http://www.tokkisystems.com</A> \
</FONT> </P>
<P><FONT SIZE=2>____________________</FONT>
<BR><FONT SIZE=2>The Load Balancing Mailing List</FONT>
<BR><FONT SIZE=2>Unsubscribe: <A \
HREF="mailto:majordomo@vegan.net?body=unsubscribe%20lb-l">mailto:majordomo@vegan.net?body=unsubscribe%20lb-l</A></FONT>
<BR><FONT SIZE=2>Archive: <A \
HREF="http://vegan.net/lb/archive" \
TARGET="_blank">http://vegan.net/lb/archive</A></FONT> <BR><FONT \
SIZE=2>LBDigest: <A HREF="http://lbdigest.com" \
TARGET="_blank">http://lbdigest.com</A></FONT> <BR><FONT SIZE=2>MRTG with SLB: \
<A HREF="http://vegan.net/MRTG" TARGET="_blank">http://vegan.net/MRTG</A></FONT> \
<BR><FONT SIZE=2>Hosted by: <A \
HREF="http://www.tokkisystems.com" \
TARGET="_blank">http://www.tokkisystems.com</A></FONT> </P>
</BODY>
</HTML>
____________________
The Load Balancing Mailing List
Unsubscribe: mailto:majordomo@vegan.net?body=unsubscribe%20lb-l
Archive: http://vegan.net/lb/archive
LBDigest: http://lbdigest.com
MRTG with SLB: http://vegan.net/MRTG
Hosted by: http://www.tokkisystems.com
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic