Wich device is the .253?
Paste here the trace route from network 10 please
From untangle you can ping any device in net 10?
- Individual Applications
Protect
Filter
Perform
Connect
Add-Ons
- Software Packages
- Complete Appliances
Wich device is the .253?
Paste here the trace route from network 10 please
From untangle you can ping any device in net 10?
Last edited by dwasserman; 08-03-2010 at 07:12 AM. Reason: reverse ping
The world is divided into 10 kinds of people, who know binary and those not
you need to either change you subnet mask from /24 to /16 or give untangle an IP alias on the 192.168.10.x network.
Untangle cannot see the 192.168.10.x network unless you give it an ip alias or change your snm to cover the 192.168.10.x network.
www.untangleappliances.com
Toll Free: 866-794-8879
UNTANGLE PLATINUM PARTNER
Follow us at spiceworks!
I paste the screenshots from the 192.168.10.1 and the Ut screenshot.
The device in the 192.168.20.253 or any .253 is a router run by a provider, Itīs out of my hands, all the non-VPN traffic is sent to 192.168.20.251, that always work fine in the other fw and it seems so also for the trace output.
In the meanwhile, Iīll check proactivens advice.
Regards,
Claudio
www.untangleappliances.com
Toll Free: 866-794-8879
UNTANGLE PLATINUM PARTNER
Follow us at spiceworks!
Exactly as you say proactivens, it works now
Thanks all for the help!
I donīt want to bother anymore, but can you explain a little bit why change the snm was necesary, and static rules werenīt enough
Anyway, it was a big help.
Regards,
Claudio
Blame linux... the linux kernel isn't a bridge, it's a b-router. It has to know it's responsible for the address ranges in question.
So you either have to add an alias, to put the server on all networks it needs to filter. Or, you widen the subnet mask to cover all of the IPs in question.
The static route is really a pointless addition. The only reason you ever need that on a bridge is to cover a remote segment.
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
NexgenAppliances.com
Phone: 866-794-8879
your welcomeSkyknight is right, untangle needs to be addressable on every network its connected to. Otherwise, it doesnt know how to communicate to that network. Static routes should be enough, but they are not. Thats just the way it is. One of the caveats of Untangle.
www.untangleappliances.com
Toll Free: 866-794-8879
UNTANGLE PLATINUM PARTNER
Follow us at spiceworks!
Really I dont finish to understand well.
If you change the netmask to 16 work ok, but generate a big broadcast domain, with the risk of saturate the vpn links with this.
I have only one installation with UT and remote private 5 sites, and config them in networking/advance/routes without any problem. No alias, no widen subnet mask, but its true also, are pure private links, not vpn.
The world is divided into 10 kinds of people, who know binary and those not
Remote segments are a different story. Those use static routes because there is another router responsible for them. The widened mask is for when you have those IP spaces transiting a single segment where Untangle resides.
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
NexgenAppliances.com
Phone: 866-794-8879