<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:www.nabble.com,2006:forum-2063</id>
	<title>Nabble - Netscreen - General</title>
	<updated>2007-09-07T07:56:52Z</updated>
	<link rel="self" type="application/atom+xml" href="http://www.nabble.com/Netscreen---General-f2063.xml" />
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Netscreen---General-f2063.html" />
	<subtitle type="html">Welcome to the &lt;a href=&quot;http://www.qorbit.net/nn/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;[nn] Netscreen mailing list&lt;/a&gt;. This list is dedicated to the sharing of knowledge regarding Netscreen products. We hope you find it helpful and use it to share your expertise as well as benefit from the experience of others as it pertains to Netscreen gear.
&lt;br&gt;&lt;br&gt;This archive has been made readonly because the misl moved. Please see &lt;a href=&quot;http://www.nabble.com/Netscreen-at-Compsoc.com-f20745.html&quot; target=&quot;_top&quot;&gt;http://www.nabble.com/Netscreen-at-Compsoc.com-f20745.html&lt;/a&gt;</subtitle>
	
<entry>
	<id>tag:www.nabble.com,2006:post-12555788</id>
	<title>DIP vs MIP</title>
	<published>2007-09-07T07:56:52Z</published>
	<updated>2007-09-07T07:56:52Z</updated>
	<author>
		<name>Hoss</name>
	</author>
	<content type="html">Hello all,
&lt;br&gt;I am new to Netscreen firewalls, I would like to know If I have a server behind fw with 10.1.1.10 and would like to do NAT to a single Public IP address, what do I need to do?
&lt;br&gt;If I have a network of 10.1.1.0 and would like to NAT the whole network to a single Public IP address what I need to do?
&lt;br&gt;in Checkpoint we do static NAT for the servers and hid NAT for the whole network, what is the case for Netscreen?
&lt;br&gt;thanks,
&lt;br&gt;Sam</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/DIP-vs-MIP-tp12555788p12555788.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-12368635</id>
	<title>NetScreen Security Manager Required</title>
	<published>2007-08-28T08:10:30Z</published>
	<updated>2007-08-28T08:10:30Z</updated>
	<author>
		<name>Jagz64</name>
	</author>
	<content type="html">&lt;br&gt;&amp;nbsp;Hi There
&lt;br&gt;&lt;br&gt;&amp;nbsp;Does any one have a copy of the software as i require it for my 5XP Router
&lt;br&gt;&lt;br&gt;&amp;nbsp;Regards, Jagz</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/NetScreen-Security-Manager-Required-tp12368635p12368635.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-12048915</id>
	<title>SA6000 with RSA and AD, Single Sign on</title>
	<published>2007-08-08T02:09:18Z</published>
	<updated>2007-08-08T02:09:18Z</updated>
	<author>
		<name>IT BOD</name>
	</author>
	<content type="html">Hi All,
&lt;br&gt;&lt;br&gt;I'm new to the forum and have searched the current posts but I can't seem to find what I'm after. &amp;nbsp;Apolgies in advance if this has already been covered.
&lt;br&gt;&lt;br&gt;I have a SA6000 connecting to a RSA Radius Server, within an AD. &amp;nbsp;I have published fileshares/teminal services connections on the IVE to resources within this AD. &amp;nbsp;Users can sucesfully authenticate to the IVE, but are then prompted to re-authenticate using their token and windows password to access these resources (rather than having it passed via RSA). &amp;nbsp;I want to have a single sign on.
&lt;br&gt;&lt;br&gt;Can anyone point me to some documentation that may be of assistance.
&lt;br&gt;&lt;br&gt;Thanks for your help.</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SA6000-with-RSA-and-AD%2C-Single-Sign-on-tp12048915p12048915.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-12014780</id>
	<title>manage from different subnet to int vlan1 in transparent mode</title>
	<published>2007-08-06T05:48:49Z</published>
	<updated>2007-08-06T05:48:49Z</updated>
	<author>
		<name>janto</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;I had problem to manage the firewall setup in transparent mode from different subnet (PC2) than int vlan1.
&lt;br&gt;topology :
&lt;br&gt;&lt;br&gt;L3 switch ---- trunk port (vlan 10 &amp; 12) ----FW----trunk port (vlan 10 &amp; 12) ----L2 switch----PC2 (vlan 10)
&lt;br&gt;&lt;br&gt;Vlan 12 on L2 switch and L3 switch configured as native vlan. 
&lt;br&gt;Int vlan1 IP address is in Vlan 12 subnet.
&lt;br&gt;&lt;br&gt;Please advice.
&lt;br&gt;Thanks and Regards,
&lt;br&gt;Janto
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/manage-from-different-subnet-to-int-vlan1-in-transparent-mode-tp12014780p12014780.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-11753688</id>
	<title>an initial Phase 1 packet arrived from an unrecognized peer gateway</title>
	<published>2007-07-23T16:04:55Z</published>
	<updated>2007-07-23T16:04:55Z</updated>
	<author>
		<name>jpnosworthy</name>
	</author>
	<content type="html">&amp;nbsp;have an lt2p over ipsec tunnel I'm trying to set up on a netscreen ns5gt. &amp;nbsp;As far as I know the setup should closely resemble what they have at &lt;a href=&quot;http://kb.juniper.net/KB4094&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://kb.juniper.net/KB4094&lt;/a&gt;&amp;nbsp; Whenever I try and connect I get the error &amp;quot;Rejected an IKE packet on untrust from 76.230.131.199:500 to 64.151.122.4:500 with cookies ..... because an initial Phase 1 packet arrived from an unrecognized peer gateway&amp;quot; &amp;nbsp;I've read that this error comes from the p1 and p2 stuff not agreeing on the outgoing interface, however everything should be set to untrust. &amp;nbsp;If anyone can spot why this is happening and tell me I would appreciate it. &amp;nbsp;My config is as follows:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;1.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; netscreen-&amp;gt; get config
&lt;br&gt;&amp;nbsp; &amp;nbsp;2.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Total Config size 7153:
&lt;br&gt;&amp;nbsp; &amp;nbsp;3.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set clock ntp
&lt;br&gt;&amp;nbsp; &amp;nbsp;4.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set clock timezone 0
&lt;br&gt;&amp;nbsp; &amp;nbsp;5.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set vrouter trust-vr sharable
&lt;br&gt;&amp;nbsp; &amp;nbsp;6.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set vrouter &amp;quot;untrust-vr&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp;7.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp; &amp;nbsp;8.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set vrouter &amp;quot;trust-vr&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp;9.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset auto-route-export
&lt;br&gt;&amp;nbsp; 10.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp; 11.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set service &amp;quot;Plesk&amp;quot; protocol tcp src-port 1-65535 dst-port 8443-8443
&lt;br&gt;&amp;nbsp; 12.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set service &amp;quot;Ensim&amp;quot; protocol tcp src-port 1-65535 dst-port 19638-19638
&lt;br&gt;&amp;nbsp; 13.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set service &amp;quot;Cpanel&amp;quot; protocol tcp src-port 1-65535 dst-port 2082-2087
&lt;br&gt;&amp;nbsp; 14.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set service &amp;quot;RDP&amp;quot; protocol tcp src-port 1-65535 dst-port 3389-3389
&lt;br&gt;&amp;nbsp; 15.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set auth-server &amp;quot;Local&amp;quot; id 0
&lt;br&gt;&amp;nbsp; 16.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set auth-server &amp;quot;Local&amp;quot; server-name &amp;quot;Local&amp;quot;
&lt;br&gt;&amp;nbsp; 17.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set auth default auth server &amp;quot;Local&amp;quot;
&lt;br&gt;&amp;nbsp; 18.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set auth radius accounting port 1646
&lt;br&gt;&amp;nbsp; 19.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set admin name &amp;quot;netscreensp&amp;quot;
&lt;br&gt;&amp;nbsp; 20.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set admin password &amp;quot;xxx&amp;quot;
&lt;br&gt;&amp;nbsp; 21.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set admin user &amp;quot;15705&amp;quot; password &amp;quot;xxx&amp;quot; privilege &amp;quot;all&amp;quot;
&lt;br&gt;&amp;nbsp; 22.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set admin auth timeout 10
&lt;br&gt;&amp;nbsp; 23.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set admin auth server &amp;quot;Local&amp;quot;
&lt;br&gt;&amp;nbsp; 24.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set admin format dos
&lt;br&gt;&amp;nbsp; 25.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;Trust&amp;quot; vrouter &amp;quot;trust-vr&amp;quot;
&lt;br&gt;&amp;nbsp; 26.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;Untrust&amp;quot; vrouter &amp;quot;trust-vr&amp;quot;
&lt;br&gt;&amp;nbsp; 27.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;VLAN&amp;quot; vrouter &amp;quot;trust-vr&amp;quot;
&lt;br&gt;&amp;nbsp; 28.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;Untrust-Tun&amp;quot; vrouter &amp;quot;trust-vr&amp;quot;
&lt;br&gt;&amp;nbsp; 29.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;Trust&amp;quot; tcp-rst
&lt;br&gt;&amp;nbsp; 30.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;Untrust&amp;quot; block
&lt;br&gt;&amp;nbsp; 31.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset zone &amp;quot;Untrust&amp;quot; tcp-rst
&lt;br&gt;&amp;nbsp; 32.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;MGT&amp;quot; block
&lt;br&gt;&amp;nbsp; 33.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;VLAN&amp;quot; block
&lt;br&gt;&amp;nbsp; 34.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset zone &amp;quot;VLAN&amp;quot; tcp-rst
&lt;br&gt;&amp;nbsp; 35.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;Untrust&amp;quot; screen tear-drop
&lt;br&gt;&amp;nbsp; 36.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;Untrust&amp;quot; screen syn-flood
&lt;br&gt;&amp;nbsp; 37.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;Untrust&amp;quot; screen ping-death
&lt;br&gt;&amp;nbsp; 38.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;Untrust&amp;quot; screen ip-filter-src
&lt;br&gt;&amp;nbsp; 39.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;Untrust&amp;quot; screen land
&lt;br&gt;&amp;nbsp; 40.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;V1-Untrust&amp;quot; screen tear-drop
&lt;br&gt;&amp;nbsp; 41.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;V1-Untrust&amp;quot; screen syn-flood
&lt;br&gt;&amp;nbsp; 42.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;V1-Untrust&amp;quot; screen ping-death
&lt;br&gt;&amp;nbsp; 43.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;V1-Untrust&amp;quot; screen ip-filter-src
&lt;br&gt;&amp;nbsp; 44.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set zone &amp;quot;V1-Untrust&amp;quot; screen land
&lt;br&gt;&amp;nbsp; 45.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set interface &amp;quot;trust&amp;quot; zone &amp;quot;Trust&amp;quot;
&lt;br&gt;&amp;nbsp; 46.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set interface &amp;quot;untrust&amp;quot; zone &amp;quot;Untrust&amp;quot;
&lt;br&gt;&amp;nbsp; 47.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset interface vlan1 ip
&lt;br&gt;&amp;nbsp; 48.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set interface trust ip 64.151.122.17/29
&lt;br&gt;&amp;nbsp; 49.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set interface trust route
&lt;br&gt;&amp;nbsp; 50.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set interface untrust ip 64.151.122.4/29
&lt;br&gt;&amp;nbsp; 51.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set interface untrust route
&lt;br&gt;&amp;nbsp; 52.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set interface untrust gateway 64.151.122.1
&lt;br&gt;&amp;nbsp; 53.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset interface vlan1 bypass-others-ipsec
&lt;br&gt;&amp;nbsp; 54.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset interface vlan1 bypass-non-ip
&lt;br&gt;&amp;nbsp; 55.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set interface trust ip manageable
&lt;br&gt;&amp;nbsp; 56.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set interface untrust ip manageable
&lt;br&gt;&amp;nbsp; 57.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set interface untrust manage ping
&lt;br&gt;&amp;nbsp; 58.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set interface untrust manage ssh
&lt;br&gt;&amp;nbsp; 59.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set interface untrust manage ssl
&lt;br&gt;&amp;nbsp; 60.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set interface untrust manage web
&lt;br&gt;&amp;nbsp; 61.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set flow tcp-mss
&lt;br&gt;&amp;nbsp; 62.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset flow tcp-syn-check
&lt;br&gt;&amp;nbsp; 63.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set domain xoopit.com
&lt;br&gt;&amp;nbsp; 64.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set hostname netscreen
&lt;br&gt;&amp;nbsp; 65.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;nbsp; 66.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set dns host dns1 216.93.160.16
&lt;br&gt;&amp;nbsp; 67.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set dns host dns2 216.93.170.17
&lt;br&gt;&amp;nbsp; 68.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set dns host dns3 0.0.0.0
&lt;br&gt;&amp;nbsp; 69.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set address &amp;quot;Trust&amp;quot; &amp;quot;inside&amp;quot; 64.151.122.16 255.255.255.248 &amp;quot;quit block for dial-up vpn user&amp;quot;
&lt;br&gt;&amp;nbsp; 70.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set address &amp;quot;Untrust&amp;quot; &amp;quot;24.6.166.160/255.255.255.255&amp;quot; 24.6.166.160 255.255.255.255
&lt;br&gt;&amp;nbsp; 71.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set ippool &amp;quot;l2tp-pool&amp;quot; 192.168.10.25 192.168.10.50
&lt;br&gt;&amp;nbsp; 72.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set user &amp;quot;james&amp;quot; uid 2
&lt;br&gt;&amp;nbsp; 73.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set user &amp;quot;james&amp;quot; ike-id u-fqdn &amp;quot;james@xoopit.com&amp;quot; share-limit 1
&lt;br&gt;&amp;nbsp; 74.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set user &amp;quot;james&amp;quot; type &amp;nbsp;ike
&lt;br&gt;&amp;nbsp; 75.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set user &amp;quot;james&amp;quot; &amp;quot;enable&amp;quot;
&lt;br&gt;&amp;nbsp; 76.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set user &amp;quot;l2tp&amp;quot; uid 6
&lt;br&gt;&amp;nbsp; 77.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set user &amp;quot;l2tp&amp;quot; type &amp;nbsp;ike l2tp
&lt;br&gt;&amp;nbsp; 78.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set user &amp;quot;l2tp&amp;quot; password &amp;quot;xxx&amp;quot;
&lt;br&gt;&amp;nbsp; 79.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset user &amp;quot;l2tp&amp;quot; type auth
&lt;br&gt;&amp;nbsp; 80.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set user &amp;quot;l2tp&amp;quot; &amp;quot;enable&amp;quot;
&lt;br&gt;&amp;nbsp; 81.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set user-group &amp;quot;l2tp-usergroup&amp;quot; id 2
&lt;br&gt;&amp;nbsp; 82.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set user-group &amp;quot;l2tp-usergroup&amp;quot; user &amp;quot;l2tp&amp;quot;
&lt;br&gt;&amp;nbsp; 83.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set ike gateway &amp;quot;james.p1&amp;quot; dialup &amp;quot;james&amp;quot; Main outgoing-interface &amp;quot;untrust&amp;quot; preshare &amp;quot;xaxE+ljtNGFXMSs9I3CHt9d3QanppbXl0Q==&amp;quot; proposal &amp;quot;pre-g1-des-sha&amp;quot;
&lt;br&gt;&amp;nbsp; 84.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset ike gateway &amp;quot;james.p1&amp;quot; nat-traversal
&lt;br&gt;&amp;nbsp; 85.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set ike gateway &amp;quot;l2tp.p1&amp;quot; dialup &amp;quot;l2tp-usergroup&amp;quot; Aggr outgoing-interface &amp;quot;untrust&amp;quot; preshare &amp;quot;TO2JjdYCNUYtzXsXL6CWL3XZdandXy/LgqWIzwSQUKgQO8S+Y1NCPMs=&amp;quot; proposal &amp;quot;pre-g2-des-sha&amp;quot;
&lt;br&gt;&amp;nbsp; 86.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset ike gateway &amp;quot;l2tp.p1&amp;quot; nat-traversal
&lt;br&gt;&amp;nbsp; 87.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set ike respond-bad-spi 1
&lt;br&gt;&amp;nbsp; 88.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset ike ikeid-enumeration
&lt;br&gt;&amp;nbsp; 89.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset ipsec access-session enable
&lt;br&gt;&amp;nbsp; 90.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set ipsec access-session maximum 5000
&lt;br&gt;&amp;nbsp; 91.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set ipsec access-session upper-threshold 0
&lt;br&gt;&amp;nbsp; 92.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set ipsec access-session lower-threshold 0
&lt;br&gt;&amp;nbsp; 93.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set ipsec access-session dead-p2-sa-timeout 0
&lt;br&gt;&amp;nbsp; 94.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset ipsec access-session log-error
&lt;br&gt;&amp;nbsp; 95.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset ipsec access-session info-exch-connected
&lt;br&gt;&amp;nbsp; 96.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset ipsec access-session use-error-log
&lt;br&gt;&amp;nbsp; 97.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set vpn &amp;quot;james.p2&amp;quot; gateway &amp;quot;james.p1&amp;quot; no-replay tunnel idletime 0 proposal &amp;quot;nopfs-esp-des-sha&amp;quot;
&lt;br&gt;&amp;nbsp; 98.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set vpn &amp;quot;l2tp.p2&amp;quot; gateway &amp;quot;l2tp.p1&amp;quot; no-replay transport idletime 0 proposal &amp;quot;nopfs-esp-des-md5&amp;quot; &amp;nbsp;&amp;quot;nopfs-esp-3des-md5&amp;quot; &amp;nbsp;&amp;quot;nopfs-esp-des-sha&amp;quot; &amp;nbsp;&amp;quot;nopfs-esp-3des-sha&amp;quot;
&lt;br&gt;&amp;nbsp; 99.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set l2tp default ippool &amp;quot;l2tp-pool&amp;quot;
&lt;br&gt;&amp;nbsp;100.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set l2tp default ppp-auth chap
&lt;br&gt;&amp;nbsp;101.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set l2tp &amp;quot;l2tp-tunnel&amp;quot; id 5 outgoing-interface untrust keepalive 60
&lt;br&gt;&amp;nbsp;102.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set url protocol websense
&lt;br&gt;&amp;nbsp;103.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;104.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 17 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Dial-Up VPN&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;ANY&amp;quot; tunnel vpn &amp;quot;l2tp.p2&amp;quot; id 10 l2tp &amp;quot;l2tp-tunnel&amp;quot;
&lt;br&gt;&amp;nbsp;105.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 17
&lt;br&gt;&amp;nbsp;106.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;107.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 16 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Dial-Up VPN&amp;quot; &amp;quot;inside&amp;quot; &amp;quot;ANY&amp;quot; tunnel vpn &amp;quot;james.p2&amp;quot; id 5
&lt;br&gt;&amp;nbsp;108.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 16
&lt;br&gt;&amp;nbsp;109.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;110.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 1 from &amp;quot;Trust&amp;quot; to &amp;quot;Untrust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;ANY&amp;quot; permit
&lt;br&gt;&amp;nbsp;111.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 1
&lt;br&gt;&amp;nbsp;112.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;113.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 2 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;ANY&amp;quot; permit
&lt;br&gt;&amp;nbsp;114.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 2 disable
&lt;br&gt;&amp;nbsp;115.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 2
&lt;br&gt;&amp;nbsp;116.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;117.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 3 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;ICMP-ANY&amp;quot; permit
&lt;br&gt;&amp;nbsp;118.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 3
&lt;br&gt;&amp;nbsp;119.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;120.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 5 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;HTTP&amp;quot; permit
&lt;br&gt;&amp;nbsp;121.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 5
&lt;br&gt;&amp;nbsp;122.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp;123.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 6 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;HTTPS&amp;quot; permit
&lt;br&gt;&amp;nbsp;124.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 6
&lt;br&gt;&amp;nbsp;125.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;126.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 7 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;SSH&amp;quot; permit
&lt;br&gt;&amp;nbsp;127.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 7
&lt;br&gt;&amp;nbsp;128.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;129.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 8 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;RDP&amp;quot; permit
&lt;br&gt;&amp;nbsp;130.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 8 disable
&lt;br&gt;&amp;nbsp;131.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 8
&lt;br&gt;&amp;nbsp;132.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;133.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 9 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;Plesk&amp;quot; permit
&lt;br&gt;&amp;nbsp;134.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 9 disable
&lt;br&gt;&amp;nbsp;135.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 9
&lt;br&gt;&amp;nbsp;136.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;137.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 10 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;Ensim&amp;quot; permit
&lt;br&gt;&amp;nbsp;138.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 10 disable
&lt;br&gt;&amp;nbsp;139.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 10
&lt;br&gt;&amp;nbsp;140.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;141.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 11 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;Cpanel&amp;quot; permit
&lt;br&gt;&amp;nbsp;142.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 11 disable
&lt;br&gt;&amp;nbsp;143.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 11
&lt;br&gt;&amp;nbsp;144.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp;145.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 12 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;SMTP&amp;quot; permit
&lt;br&gt;&amp;nbsp;146.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 12 disable
&lt;br&gt;&amp;nbsp;147.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 12
&lt;br&gt;&amp;nbsp;148.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;149.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 13 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;POP3&amp;quot; permit
&lt;br&gt;&amp;nbsp;150.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 13 disable
&lt;br&gt;&amp;nbsp;151.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 13
&lt;br&gt;&amp;nbsp;152.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;153.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 14 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;DNS&amp;quot; permit
&lt;br&gt;&amp;nbsp;154.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 14 disable
&lt;br&gt;&amp;nbsp;155.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 14
&lt;br&gt;&amp;nbsp;156.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;157.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 15 from &amp;quot;Untrust&amp;quot; to &amp;quot;Trust&amp;quot; &amp;nbsp;&amp;quot;Any&amp;quot; &amp;quot;Any&amp;quot; &amp;quot;ANY&amp;quot; deny
&lt;br&gt;&amp;nbsp;158.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set policy id 15
&lt;br&gt;&amp;nbsp;159.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;160.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set monitor cpu 100
&lt;br&gt;&amp;nbsp;161.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set syslog config &amp;quot;216.93.160.97&amp;quot;
&lt;br&gt;&amp;nbsp;162.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set syslog config &amp;quot;216.93.160.97&amp;quot; facilities local0 local0
&lt;br&gt;&amp;nbsp;163.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set syslog enable
&lt;br&gt;&amp;nbsp;164.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set global-pro policy-manager primary outgoing-interface untrust
&lt;br&gt;&amp;nbsp;165.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set global-pro policy-manager secondary outgoing-interface untrust
&lt;br&gt;&amp;nbsp;166.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set nsmgmt bulkcli reboot-timeout 60
&lt;br&gt;&amp;nbsp;167.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set ssh version v2
&lt;br&gt;&amp;nbsp;168.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set ssh enable
&lt;br&gt;&amp;nbsp;169.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set config lock timeout 5
&lt;br&gt;&amp;nbsp;170.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set ntp server &amp;quot;216.93.160.62&amp;quot;
&lt;br&gt;&amp;nbsp;171.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set modem speed 115200
&lt;br&gt;&amp;nbsp;172.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set modem retry 3
&lt;br&gt;&amp;nbsp;173.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set modem interval 10
&lt;br&gt;&amp;nbsp;174.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set modem idle-time 10
&lt;br&gt;&amp;nbsp;175.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set snmp port listen 161
&lt;br&gt;&amp;nbsp;176.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set snmp port trap 162
&lt;br&gt;&amp;nbsp;177.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set vrouter &amp;quot;untrust-vr&amp;quot;
&lt;br&gt;&amp;nbsp;178.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;179.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set vrouter &amp;quot;trust-vr&amp;quot;
&lt;br&gt;&amp;nbsp;180.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; unset add-default-route
&lt;br&gt;&amp;nbsp;181.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;182.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set vrouter &amp;quot;untrust-vr&amp;quot;
&lt;br&gt;&amp;nbsp;183.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;184.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; set vrouter &amp;quot;trust-vr&amp;quot;
&lt;br&gt;&amp;nbsp;185.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; exit
&lt;br&gt;&amp;nbsp;186.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; netscreen-&amp;gt; </content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/an-initial-Phase-1-packet-arrived-from-an-unrecognized-peer-gateway-tp11753688p11753688.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-11744462</id>
	<title>Encryption Citrix Problem</title>
	<published>2007-07-23T08:20:21Z</published>
	<updated>2007-07-23T08:20:21Z</updated>
	<author>
		<name>Iban</name>
	</author>
	<content type="html">Hi there,
&lt;br&gt;&lt;br&gt;Just like to check if anyone have faced any issue regarding Netscreen encryption and citrix issue.
&lt;br&gt;&lt;br&gt;I have a site to site VPN tunnel established on two remote location. Citrix server sits on one end and users on the other. Other traffics working fine. It is only the citrix user are constantly getting disconnected at varying time interval.
&lt;br&gt;&lt;br&gt;Also is there any way to monitor the traffic flow since it is not happening at a fix time. Or will in show in the event or traffic logs?
&lt;br&gt;&lt;br&gt;Any workaround or troubleshooting ideas are welcome.</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Encryption-Citrix-Problem-tp11744462p11744462.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-11547601</id>
	<title>Traffic Shaping in Transparent Mode with NS5GT</title>
	<published>2007-07-11T13:46:54Z</published>
	<updated>2007-07-11T13:46:54Z</updated>
	<author>
		<name>Johnk</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;One of my clients is manages a building floor where about 100 offices share a single T-1. &amp;nbsp;One of their tenants is sucking up most of the bandwidth and my client wants their usage throttled. &amp;nbsp;I've set up traffic shaping to throttle bandwidth in NAT mode, but I've never set up one of these appliances in filtering mode. &amp;nbsp;Is this just a matter of setting the device in transparent mode and defining a policy? &amp;nbsp;Any advice is appreciated.
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;John</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Traffic-Shaping-in-Transparent-Mode-with-NS5GT-tp11547601p11547601.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-11515421</id>
	<title>Netscreen 5XT issues</title>
	<published>2007-07-10T00:18:03Z</published>
	<updated>2007-07-10T00:18:03Z</updated>
	<author>
		<name>DeanB</name>
	</author>
	<content type="html">Hi guys, I have a Netscreen 5XT that hadnt been used for a few years and no one knew IP address, user, pass etc. I cannot get any response from any console session, ie the screen is always blank. The status light continues to blink green, even after a power recycle. It doesn't matter how many times I press the button in the pinhole, the unit will not reset, and without console access I am at a bit of a loss in regard to my next course of action...any ideas? :)
&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;&lt;br&gt;Dean</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Netscreen-5XT-issues-tp11515421p11515421.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-10086523</id>
	<title>Re: Does anyone on the list have experience with firewall log analyzers to monitor firewall...</title>
	<published>2007-04-19T13:25:53Z</published>
	<updated>2007-04-19T13:25:53Z</updated>
	<author>
		<name>Tim E</name>
	</author>
	<content type="html">I think what you&amp;#39;re looking to do here will require a few programs.&lt;br&gt;&lt;br&gt;1) A logging analyzer (for the completed connections)&lt;br&gt;&amp;nbsp;There are a few free ones, I would suggest giving them a shot. I personally haven&amp;#39;t used any of them. 
&lt;br&gt;&lt;br&gt;2) A traffic snmp monitor&lt;br&gt;&amp;nbsp;Personally I use Cacti for this, however there are many various snmp monitors. This will only give you a general view of traffic on each interface, not on a per policy hit.&lt;br&gt;&lt;br&gt;3) Perhaps a real time session analyzer (during attacks, high traffic, etc.)
&lt;br&gt;I wrote a program called NSSA (Netscreen Session Analyzer) This basically reports on a live session table that you download by hand and gives you such information as connections/ports/source/dest/ etc.. This is public and free.
&lt;br&gt;&lt;br&gt;&lt;br&gt;On the other side, it would be a lot easier to use a Network General Sniffer type application. These do everything you request (short of policy denies/allows on the firewall) at a network level. &lt;br&gt;&lt;br&gt;This is a general overview of the options I think are viable. If you have any questions or want to talk about them in depth feel free to ask :)
&lt;br&gt;&lt;br&gt;Tim Eberhard&lt;br&gt;&lt;br&gt;&lt;div&gt;&lt;span class=&quot;gmail_quote&quot;&gt;On 4/19/07, &lt;b class=&quot;gmail_sendername&quot;&gt;Jacob, Raymond A Jr&lt;/b&gt; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10086523&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;raymond.jacob@...&lt;/a&gt;&amp;gt; wrote:&lt;/span&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
Subject:&amp;nbsp;&amp;nbsp;Does anyone on the list have experience with&amp;nbsp;&amp;nbsp;firewall log&lt;br&gt;analyzers to monitor firewall bandwidth and service utilization.&lt;br&gt;&lt;br&gt;-----------------------------------------------&lt;br&gt;&lt;br&gt;Date: Thu, 19 Apr 2007 05:18:20 -0500
&lt;br&gt;From: &amp;quot;Tim Eberhard&amp;quot; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10086523&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;xmin0s@...&lt;/a&gt;&amp;gt;&lt;br&gt;Subject: Re: [nn] Does anyone on the list have experience with these&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;firewall log analyzer programs?&lt;br&gt;To: &amp;quot;Jacob, Raymond A Jr&amp;quot; &amp;lt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10086523&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;raymond.jacob@...&lt;/a&gt;&amp;gt;&lt;br&gt;Cc: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10086523&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;Message-ID:&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10086523&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;2c52b84e0704190318h46037839udd1d8f39fa01e868@...&lt;/a&gt;&amp;gt;&lt;br&gt;Content-Type: text/plain; charset=&amp;quot;iso-8859-1&amp;quot;&lt;br&gt;&lt;br&gt;What are you looking to solve? What kind of information are you looking&lt;br&gt;to&lt;br&gt;gather?
&lt;br&gt;&amp;gt;&amp;gt;I need to know how much traffic each service uses.&lt;br&gt;&amp;gt;&amp;gt;I need to know what hosts use a particular service.&lt;br&gt;&amp;gt;&amp;gt;I need to know how much traffic hosts use for a service.&lt;br&gt;&amp;gt;&amp;gt;i.e. for http: host-a tx/rx 100MB/day while host-b tx/rx 5MB/day.
&lt;br&gt;&amp;gt;&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;I would like that information in a bar graph.&lt;br&gt;&amp;gt;&amp;gt;I need to know what hosts and ports were denied access by the&lt;br&gt;firewall.&lt;br&gt;&amp;gt;&amp;gt;I need to know the a graph of traffic over a period of days,weeks,
&lt;br&gt;months&lt;br&gt;&amp;gt;&amp;gt;for all traffic, for hosts, and for services.&lt;br&gt;&amp;gt;&amp;gt;I need to know how much traffic(bandwidth), services(ports), and hosts&lt;br&gt;&amp;gt;&amp;gt;are used per VPN.&lt;br&gt;&amp;gt;&amp;gt;I need to know what web sites are accessed.
&lt;br&gt;&amp;gt;&amp;gt;I need to know what dns queries were made by the users.&lt;br&gt;&lt;br&gt;&amp;gt;&amp;gt;Thank you,&lt;br&gt;&amp;gt;&amp;gt;raymond&lt;br&gt;_______________________________________________&lt;br&gt;nn mailing list&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10086523&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10086523&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Re%3A-Does-anyone-on-the-list-have-experience-with-firewall-log-analyzers-to-monitor-firewall...-tp10086175p10086523.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-10086175</id>
	<title>Re: Does anyone on the list have experience with firewall log analyzers to monitor firewall...</title>
	<published>2007-04-19T13:01:36Z</published>
	<updated>2007-04-19T13:01:36Z</updated>
	<author>
		<name>jacobsladder</name>
	</author>
	<content type="html">Subject: &amp;nbsp;Does anyone on the list have experience with &amp;nbsp;firewall log
&lt;br&gt;analyzers to monitor firewall bandwidth and service utilization.
&lt;br&gt;&lt;br&gt;-----------------------------------------------
&lt;br&gt;&lt;br&gt;Date: Thu, 19 Apr 2007 05:18:20 -0500
&lt;br&gt;From: &amp;quot;Tim Eberhard&amp;quot; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10086175&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;xmin0s@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Subject: Re: [nn] Does anyone on the list have experience with these
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; firewall log analyzer programs?
&lt;br&gt;To: &amp;quot;Jacob, Raymond A Jr&amp;quot; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10086175&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;raymond.jacob@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Cc: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10086175&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;Message-ID:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10086175&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;2c52b84e0704190318h46037839udd1d8f39fa01e868@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Content-Type: text/plain; charset=&amp;quot;iso-8859-1&amp;quot;
&lt;br&gt;&lt;br&gt;What are you looking to solve? What kind of information are you looking
&lt;br&gt;to
&lt;br&gt;gather?
&lt;br&gt;&amp;gt;&amp;gt;I need to know how much traffic each service uses.
&lt;br&gt;&amp;gt;&amp;gt;I need to know what hosts use a particular service.
&lt;br&gt;&amp;gt;&amp;gt;I need to know how much traffic hosts use for a service.
&lt;br&gt;&amp;gt;&amp;gt;i.e. for http: host-a tx/rx 100MB/day while host-b tx/rx 5MB/day.
&lt;br&gt;&amp;gt;&amp;gt;	I would like that information in a bar graph.
&lt;br&gt;&amp;gt;&amp;gt;I need to know what hosts and ports were denied access by the
&lt;br&gt;firewall.
&lt;br&gt;&amp;gt;&amp;gt;I need to know the a graph of traffic over a period of days,weeks,
&lt;br&gt;months
&lt;br&gt;&amp;gt;&amp;gt;for all traffic, for hosts, and for services.
&lt;br&gt;&amp;gt;&amp;gt;I need to know how much traffic(bandwidth), services(ports), and hosts
&lt;br&gt;&amp;gt;&amp;gt;are used per VPN.
&lt;br&gt;&amp;gt;&amp;gt;I need to know what web sites are accessed.
&lt;br&gt;&amp;gt;&amp;gt;I need to know what dns queries were made by the users.
&lt;br&gt;&lt;br&gt;&amp;gt;&amp;gt;Thank you,
&lt;br&gt;&amp;gt;&amp;gt;raymond
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10086175&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Re%3A-Does-anyone-on-the-list-have-experience-with-firewall-log-analyzers-to-monitor-firewall...-tp10086175p10086175.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-10082329</id>
	<title>Re: Student assignments voor 5GT</title>
	<published>2007-04-19T10:34:26Z</published>
	<updated>2007-04-19T10:34:26Z</updated>
	<author>
		<name>Badu Jack</name>
	</author>
	<content type="html">&lt;html&gt;
&lt;head&gt;

&lt;/head&gt;
&lt;body&gt;Dear Oquendo,&lt;BR&gt;
&amp;nbsp;&lt;BR&gt;
Maybe my request is not clear enough.&lt;BR&gt;
First of all I am not a teacher. I just&lt;BR&gt;
got an assignment from the college where I study&lt;BR&gt;
to make some instructions how to use the &lt;BR&gt;
NS-5GT in combination with network lab we have.&lt;BR&gt;
I have writen already the instructions for some basic&lt;BR&gt;
configuration and the students and myself&amp;nbsp;can start 'play' with it.&lt;BR&gt;
&amp;nbsp;&lt;BR&gt;
Wat I am looking for is some good scenarios for&lt;BR&gt;
further hands on excercise. &lt;BR&gt;
&amp;nbsp;&lt;BR&gt;
Cheers again,&lt;BR&gt;
&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&amp;nbsp;&lt;BR&gt;

&lt;HR id=stopSpelling&gt;
&lt;BR&gt;
&amp;gt; Date: Thu, 19 Apr 2007 09:11:16 -0400&lt;div class='shrinkable-quote'&gt;&lt;BR&gt;&amp;gt; From: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10082329&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sil@...&lt;/a&gt;&lt;BR&gt;&amp;gt; To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10082329&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;badu1000@...&lt;/a&gt;&lt;BR&gt;&amp;gt; CC: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10082329&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;BR&gt;&amp;gt; Subject: Re: [nn] Student assignments voor 5GT&lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; Badu Jack wrote:&lt;BR&gt;&amp;gt; &amp;gt; Dear Guys,&lt;BR&gt;&amp;gt; &amp;gt; &lt;BR&gt;&amp;gt; &amp;gt; At the moment I am writing a firewall and VPN/IPsec lab. assignments&lt;BR&gt;&amp;gt; &amp;gt; for the ICT students as part of my graduation.&lt;BR&gt;&amp;gt; &amp;gt; &lt;BR&gt;&amp;gt; &amp;gt; Can somebody help with some easy to learn configuration assignments for&lt;BR&gt;&amp;gt; &amp;gt; firewalls and VPN with NetSCreen 5GT.&lt;BR&gt;&amp;gt; &amp;gt; &lt;BR&gt;&amp;gt; &amp;gt; Cheers&lt;BR&gt;&amp;gt; &amp;gt;&lt;BR&gt;&amp;gt; &amp;gt; ------------------------------------------------------------------------&lt;BR&gt;&amp;gt; &amp;gt; Windows Live Messenger het beste van de toekomst Download NU! Windows &lt;BR&gt;&amp;gt; &amp;gt; Live Messenger! &lt;BR&gt;&amp;gt; &amp;gt; &amp;lt;http://imagine-msn.com/messenger/launch80/default.aspx?locale=nl-nl&amp;amp;source=joinmsncom/messenger&amp;gt; &lt;BR&gt;&amp;gt; &amp;gt;&lt;BR&gt;&amp;gt; &amp;gt; ------------------------------------------------------------------------&lt;BR&gt;&amp;gt; &amp;gt;&lt;BR&gt;&amp;gt; &amp;gt; _______________________________________________&lt;BR&gt;&amp;gt; &amp;gt; nn mailing list&lt;BR&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10082329&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;BR&gt;&amp;gt; &amp;gt; http://qorbit.net/mailman/listinfo/nn&lt;BR&gt;&amp;gt; &amp;gt; &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; This makes little sense... So let me get this right... YOU'RE teaching a &lt;BR&gt;&amp;gt; class...&lt;BR&gt;&amp;gt; Yet you don't know a thing about the subject you're teaching? I hope I never&lt;BR&gt;&amp;gt; attend any of your seminars or classes. Thanks, I needed a picker upper this&lt;BR&gt;&amp;gt; morning...&lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; -- &lt;BR&gt;&amp;gt; ====================================================&lt;BR&gt;&amp;gt; J. Oquendo&lt;BR&gt;&amp;gt; http://pgp.mit.edu:11371/pks/lookup?op=get&amp;amp;search=0x1383A743&lt;BR&gt;&amp;gt; sil . infiltrated @ net http://www.infiltrated.net &lt;BR&gt;&amp;gt; &lt;BR&gt;&amp;gt; The happiness of society is the end of government.&lt;BR&gt;&amp;gt; John Adams&lt;BR&gt;&amp;gt; &lt;/div&gt;&lt;BR&gt;&lt;br /&gt;&lt;hr /&gt;De nieuwe Hotmail: Nu 2gb aan opslag - dat zijn maar liefst 1000 foto's - en nog steeds gratis! &lt;a href='http://imagine-windowslive.com/mail/launch/default.aspx?Locale=nl-nl)' target='_new' rel=&quot;nofollow&quot;&gt;Windows Live Hotmail&lt;/a&gt;&lt;/body&gt;
&lt;/html&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10082329&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Student-assignments-voor-5GT-tp10074194p10082329.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-10078599</id>
	<title>Re: Student assignments voor 5GT</title>
	<published>2007-04-19T07:11:16Z</published>
	<updated>2007-04-19T07:11:16Z</updated>
	<author>
		<name>J. Oquendo</name>
	</author>
	<content type="html">Badu Jack wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Dear Guys,
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; At the moment I am writing a firewall and VPN/IPsec lab. assignments
&lt;br&gt;&amp;gt; for the ICT students as part of my graduation.
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; Can somebody help with some easy to learn configuration assignments for
&lt;br&gt;&amp;gt; firewalls and VPN with NetSCreen 5GT.
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; Cheers
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Windows Live Messenger het beste van de toekomst Download NU! Windows 
&lt;br&gt;&amp;gt; Live Messenger! 
&lt;br&gt;&amp;gt; &amp;lt;&lt;a href=&quot;http://imagine-msn.com/messenger/launch80/default.aspx?locale=nl-nl&amp;source=joinmsncom/messenger&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://imagine-msn.com/messenger/launch80/default.aspx?locale=nl-nl&amp;source=joinmsncom/messenger&lt;/a&gt;&amp;gt; 
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; nn mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10078599&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;&lt;/div&gt;This makes little sense... So let me get this right... YOU'RE teaching a 
&lt;br&gt;class...
&lt;br&gt;Yet you don't know a thing about the subject you're teaching? I hope I never
&lt;br&gt;attend any of your seminars or classes. Thanks, I needed a picker upper this
&lt;br&gt;morning...
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;====================================================
&lt;br&gt;J. Oquendo
&lt;br&gt;&lt;a href=&quot;http://pgp.mit.edu:11371/pks/lookup?op=get&amp;search=0x1383A743&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pgp.mit.edu:11371/pks/lookup?op=get&amp;search=0x1383A743&lt;/a&gt;&lt;br&gt;sil . infiltrated @ net &lt;a href=&quot;http://www.infiltrated.net&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.infiltrated.net&lt;/a&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;The happiness of society is the end of government.
&lt;br&gt;John Adams
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10078599&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://www.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (6K) &lt;a href=&quot;http://www.nabble.com/attachment/10078599/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Student-assignments-voor-5GT-tp10074194p10078599.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-10075535</id>
	<title>Re: Does anyone on the list have experience with these firewall log analyzer programs?</title>
	<published>2007-04-19T04:18:20Z</published>
	<updated>2007-04-19T04:18:20Z</updated>
	<author>
		<name>Tim E</name>
	</author>
	<content type="html">What are you looking to solve? What kind of information are you looking to gather?&lt;br&gt;&lt;br&gt;&lt;div&gt;&lt;span class=&quot;gmail_quote&quot;&gt;On 4/18/07, &lt;b class=&quot;gmail_sendername&quot;&gt;Jacob, Raymond A Jr&lt;/b&gt; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10075535&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;raymond.jacob@...&lt;/a&gt;&amp;gt; wrote:&lt;/span&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;I was googling for firewall log analyzer programs and found the
&lt;br&gt;following:&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.marshal.com/pages/firewallsuite.asp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.marshal.com/pages/firewallsuite.asp&lt;/a&gt; * mentioned in Netscreen&lt;br&gt;documentation was sold by NetIQ&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.stonylakesolutions.com/sls/supported%20firewalls.jsp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;
http://www.stonylakesolutions.com/sls/supported%20firewalls.jsp&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.eventid.net/firegen/firegenns.asp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.eventid.net/firegen/firegenns.asp&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://manageengine.adventnet.com/products/firewall/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;
http://manageengine.adventnet.com/products/firewall/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://manageengine.adventnet.com/products/firewall/firewall-reports.htm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://manageengine.adventnet.com/products/firewall/firewall-reports.htm
&lt;/a&gt;&lt;br&gt;l&lt;br&gt;&lt;br&gt;&lt;br&gt;Does anyone on the list have experience with these firewall log analyzer&lt;br&gt;programs?&lt;br&gt;If so can you share your experience with me?&lt;br&gt;&lt;br&gt;Thank you&lt;br&gt;Raymond&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10075535&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10075535&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Does-anyone-on-the-list-have-experience-with-these-firewall-log-analyzer-programs--tp10071877p10075535.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-10074194</id>
	<title>Student assignments voor 5GT</title>
	<published>2007-04-19T02:33:15Z</published>
	<updated>2007-04-19T02:33:15Z</updated>
	<author>
		<name>Badu Jack</name>
	</author>
	<content type="html">&lt;html&gt;
&lt;head&gt;

&lt;/head&gt;
&lt;body&gt;Dear Guys,&lt;BR&gt;
&amp;nbsp;&lt;BR&gt;
At the moment I am writing a firewall and VPN/IPsec&amp;nbsp;lab. assignments&lt;BR&gt;
for the ICT students as part of my graduation.&lt;BR&gt;
&amp;nbsp;&lt;BR&gt;
Can somebody help with some easy to learn configuration assignments for&lt;BR&gt;
firewalls and VPN with NetSCreen 5GT.&lt;BR&gt;
&amp;nbsp;&lt;BR&gt;
Cheers&lt;BR&gt;&lt;br /&gt;&lt;hr /&gt;Windows Live Messenger het beste van de toekomst Download NU! &lt;a href='http://imagine-msn.com/messenger/launch80/default.aspx?locale=nl-nl&amp;source=joinmsncom/messenger' target='_new' rel=&quot;nofollow&quot;&gt;Windows Live Messenger!&lt;/a&gt;&lt;/body&gt;
&lt;/html&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10074194&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Student-assignments-voor-5GT-tp10074194p10074194.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-10071877</id>
	<title>Does anyone on the list have experience with these firewall log analyzer programs?</title>
	<published>2007-04-18T22:56:11Z</published>
	<updated>2007-04-18T22:56:11Z</updated>
	<author>
		<name>jacobsladder</name>
	</author>
	<content type="html">I was googling for firewall log analyzer programs and found the
&lt;br&gt;following:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.marshal.com/pages/firewallsuite.asp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.marshal.com/pages/firewallsuite.asp&lt;/a&gt;&amp;nbsp;* mentioned in Netscreen
&lt;br&gt;documentation was sold by NetIQ
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.stonylakesolutions.com/sls/supported%20firewalls.jsp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.stonylakesolutions.com/sls/supported%20firewalls.jsp&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.eventid.net/firegen/firegenns.asp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.eventid.net/firegen/firegenns.asp&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://manageengine.adventnet.com/products/firewall/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://manageengine.adventnet.com/products/firewall/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://manageengine.adventnet.com/products/firewall/firewall-reports.htm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://manageengine.adventnet.com/products/firewall/firewall-reports.htm&lt;/a&gt;&lt;br&gt;l
&lt;br&gt;&lt;br&gt;&lt;br&gt;Does anyone on the list have experience with these firewall log analyzer
&lt;br&gt;programs?
&lt;br&gt;If so can you share your experience with me?
&lt;br&gt;&lt;br&gt;Thank you
&lt;br&gt;Raymond
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=10071877&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Does-anyone-on-the-list-have-experience-with-these-firewall-log-analyzer-programs--tp10071877p10071877.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9913393</id>
	<title>Re: Netscreen 5-XP firmware..</title>
	<published>2007-04-09T21:32:35Z</published>
	<updated>2007-04-09T21:32:35Z</updated>
	<author>
		<name>Marty E.</name>
	</author>
	<content type="html">Thank you to all that replied. &amp;nbsp;I appreciate it.
&lt;br&gt;&lt;br&gt;Marty
&lt;br&gt;&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;Marty E. wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;OK, so the 5-XP has been EOL for some time, as is support. &amp;nbsp;I know this already. &amp;nbsp;I've contacted Juniper and been as nice as I could be, but they will not provide the latest firmware for version 5 (r11) hardware. &amp;nbsp;Nor will they allow me to purchase a support contract.
&lt;br&gt;&lt;br&gt;Does anyone happen to have a previously downloaded copy of r11 laying around?
&lt;br&gt;&lt;br&gt;I was hoping that I could convince support that since they have abandoned the product altogether, providing the last firmware revision to the public would be of no consequence. &amp;nbsp;Unfortunately, that opinion is not shared.
&lt;br&gt;&lt;br&gt;I would greatly appreciate it if anyone happened to have this file on hand.
&lt;br&gt;&lt;br&gt;Thank you.
&lt;br&gt;&lt;br&gt;Marty
&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Netscreen-5-XP-firmware..-tp9879822p9913393.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9908444</id>
	<title>Re: Polling date and time via SNMP on a Netscreen?</title>
	<published>2007-04-09T12:29:33Z</published>
	<updated>2007-04-09T12:29:33Z</updated>
	<author>
		<name>Sean Knox</name>
	</author>
	<content type="html">Sean Knox wrote:
&lt;br&gt;&amp;gt; Anyone know how to query a Netscreen via SNMP for the date and time? 
&lt;br&gt;&amp;gt; I've not had luck figuring it out.
&lt;br&gt;&lt;br&gt;FWIW, it's not possible to do this currently. I did put in a feature 
&lt;br&gt;request to our SE, so hopefully it'll be possible in the future.
&lt;br&gt;&lt;br&gt;sk
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9908444&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Polling-date-and-time-via-SNMP-on-a-Netscreen--tp9687557p9908444.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9879822</id>
	<title>Netscreen 5-XP firmware..</title>
	<published>2007-04-06T17:44:15Z</published>
	<updated>2007-04-06T17:44:15Z</updated>
	<author>
		<name>Marty E.</name>
	</author>
	<content type="html">OK, so the 5-XP has been EOL for some time, as is support. &amp;nbsp;I know this already. &amp;nbsp;I've contacted Juniper and been as nice as I could be, but they will not provide the latest firmware for version 5 (r11) hardware. &amp;nbsp;Nor will they allow me to purchase a support contract.
&lt;br&gt;&lt;br&gt;Does anyone happen to have a previously downloaded copy of r11 laying around?
&lt;br&gt;&lt;br&gt;I was hoping that I could convince support that since they have abandoned the product altogether, providing the last firmware revision to the public would be of no consequence. &amp;nbsp;Unfortunately, that opinion is not shared.
&lt;br&gt;&lt;br&gt;I would greatly appreciate it if anyone happened to have this file on hand.
&lt;br&gt;&lt;br&gt;Thank you.
&lt;br&gt;&lt;br&gt;Marty
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Netscreen-5-XP-firmware..-tp9879822p9879822.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9855022</id>
	<title>AV experiences on SSG500</title>
	<published>2007-04-05T05:56:24Z</published>
	<updated>2007-04-05T05:56:24Z</updated>
	<author>
		<name>Dejan Rotula</name>
	</author>
	<content type="html">&lt;html xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;meta http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 11 (filtered medium)&quot;&gt;


&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=maroon face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:maroon'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:black'&gt;Any experiences with AV and AntiSpam
deployed on SSG500 concerning throughput, cpu performance, latency and &amp;#8211;
optimal number of users (ie. PCs) in LAN protected that way?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:black'&gt;By deployed I primary think of smtp
protection and http/ftp/ protection&amp;#8230;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:black'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:black'&gt;I don&amp;#8217;t see any issues so far for
LAN of 50 users, but I am interested in some real experiences (scalability) for
network of 500 or even 5000 users?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:black'&gt;Greetings, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:
10.0pt;font-family:Arial;color:black'&gt;Dejan &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;&lt;font size=2 color=&quot;#006db4&quot; face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial;color:#006DB4'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;font size=3 face=&quot;Times New Roman&quot;&gt;&lt;span style='font-size:
12.0pt'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9855022&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/AV-experiences-on-SSG500-tp9855022p9855022.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9847353</id>
	<title>Re: L2TP Dialup</title>
	<published>2007-04-04T17:08:34Z</published>
	<updated>2007-04-04T17:08:34Z</updated>
	<author>
		<name>tommy.baumann</name>
	</author>
	<content type="html">Hello,
&lt;br&gt;&lt;br&gt;I got a netscreen 5gt with l2tp and windows XP to &amp;nbsp;work. &amp;nbsp;L2TP needs to be created like in the netscreen-document Volume 5:
&lt;br&gt;Virtual Private Networks
&lt;br&gt;Release 5.4.0, Rev. C.
&lt;br&gt;&lt;br&gt;There is one setting in Windows XP to disable IP-SEC:
&lt;br&gt;&lt;br&gt;1.	Starten Sie den Registrierungs-Editor.
&lt;br&gt;2.	Klicken Sie auf den folgenden Unterschlüssel in der Registrierung:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Rasman\Parameters
&lt;br&gt;3.	Klicken Sie im Menü Bearbeiten auf Wert hinzufügen.
&lt;br&gt;4.	Geben Sie prohibitipsec in das Feld Name ein, klicken Sie auf REG_DWORD im Feld Typ und dann auf OK.
&lt;br&gt;5.	In das Feld Daten geben Sie 1 ein. Klicken Sie dann auf OK.
&lt;br&gt;6.	Beenden Sie den Registrierungseditor. Starten Sie anschließend den Computer neu.
&lt;br&gt;&lt;br&gt;I found this only in german, but just add this key to the registry &amp;nbsp;HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Rasman\Parameters -&amp;gt; &amp;nbsp;prohibitipsec (DWORD)
&lt;br&gt;set it to 1 and reboot the PC. After that my VPN was working.
&lt;br&gt;&lt;br&gt;Does anybody get the L2TPIPSEC stuff to work. I don't want this connection unsecured !
&lt;br&gt;&lt;br&gt;regards,
&lt;br&gt;&lt;br&gt;Thomas</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/L2TP-Dialup-tp9203237p9847353.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9739164</id>
	<title>Re: Split Tunnel VPNs With Assigned DNS Servers</title>
	<published>2007-03-29T11:27:37Z</published>
	<updated>2007-03-29T11:27:37Z</updated>
	<author>
		<name>Alan Strassberg</name>
	</author>
	<content type="html">Check out DNS Proxy (but not sure if this is available in 5.0). I use this with Site-to-Site VPNs&lt;br&gt;&lt;br&gt;You can, for example, send queries for &lt;a href=&quot;http://foo.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;foo.com&lt;/a&gt; to internal servers while all other requests to the ISP.
&lt;br&gt;Great feature. Be sure you point to the Netscreen for DNS for this to work.&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;div&gt;&lt;span class=&quot;gmail_quote&quot;&gt;On 3/27/07, &lt;b class=&quot;gmail_sendername&quot;&gt;Devon True&lt;/b&gt; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9739164&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;devon+nnlist@...&lt;/a&gt;&amp;gt; wrote:&lt;/span&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;All:&lt;br&gt;&lt;br&gt;We have a customer who uses a Netscreen 5GT running 
5.0.0r8.1 that has&lt;br&gt;some dialup VPN users. The users run the Netscreen Remote software on&lt;br&gt;their PCs and the VPN connections work fine. I was recently asked if we&lt;br&gt;could assign internal DNS servers to the VPN users when they connect. I
&lt;br&gt;went to VPNs &amp;gt; AutoKey Advanced &amp;gt; XAuth Settings and configured the two&lt;br&gt;requested DNS servers. However, when users connect, they did not get the&lt;br&gt;assigned DNS servers. I found out that I had to assign a pool of IPs to
&lt;br&gt;the XAuth Settings window for the Netscreen to pass the DNS servers. The&lt;br&gt;issue with this is that *all* Internet traffic gets routed to the&lt;br&gt;Netscreen and not just VPN traffic. I also saw &amp;quot;Query Client Settings on
&lt;br&gt;Default Server&amp;quot; on the XAuth Settings but I am unable to check that box.&lt;br&gt;&lt;br&gt;The customer asked about split tunneling and my understanding is that is&lt;br&gt;what the Netscreen was doing in the first place; VPN traffic goes across
&lt;br&gt;the VPN and all other traffic goes out the normal Internet path.&lt;br&gt;However, this method did not assign the internal DNS servers.&lt;br&gt;&lt;br&gt;Any suggestions on how to accomplish this?&lt;br&gt;&lt;br&gt;The Netscreen Remote software is 
8.0.&lt;br&gt;&lt;br&gt;--&lt;br&gt;Devon&lt;br&gt;_______________________________________________&lt;br&gt;nn mailing list&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9739164&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn
&lt;/a&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9739164&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Split-Tunnel-VPNs-With-Assigned-DNS-Servers-tp9699523p9739164.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9732281</id>
	<title>Re: How to reduce MTU for a VPN tunnel?</title>
	<published>2007-03-29T05:53:37Z</published>
	<updated>2007-03-29T05:53:37Z</updated>
	<author>
		<name>Marc Haber-6</name>
	</author>
	<content type="html">On Tue, Mar 27, 2007 at 01:58:43PM -0500, Tim Eberhard wrote:
&lt;br&gt;&amp;gt; The MTU setting is a system wide configuration. To view this use the &amp;quot;get
&lt;br&gt;&amp;gt; envar&amp;quot; command.
&lt;br&gt;&lt;br&gt;I am not sure whether reducing the system-wide MTU of the netscreen
&lt;br&gt;device is going to help here. The MTU of an IPSEC tunnel is always
&lt;br&gt;going to be smaller than that, and in the current case, the client
&lt;br&gt;does not feel like sending a large packet over the tunnel.
&lt;br&gt;&lt;br&gt;Greetings
&lt;br&gt;Marc
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;-----------------------------------------------------------------------------
&lt;br&gt;Marc Haber &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;I don't trust Computers. They | Mailadresse im Header
&lt;br&gt;Mannheim, Germany &amp;nbsp;| &amp;nbsp;lose things.&amp;quot; &amp;nbsp; &amp;nbsp;Winona Ryder | Fon: *49 621 72739834
&lt;br&gt;Nordisch by Nature | &amp;nbsp;How to make an American Quilt | Fax: *49 621 72739835
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9732281&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-reduce-MTU-for-a-VPN-tunnel--tp9641863p9732281.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9728421</id>
	<title>Re: NSR Client 10.3.5 blue screening on installation</title>
	<published>2007-03-29T01:12:55Z</published>
	<updated>2007-03-29T01:12:55Z</updated>
	<author>
		<name>Csongradi Eszter</name>
	</author>
	<content type="html">Hi Marc,
&lt;br&gt;&lt;br&gt;Uninstall the ThinkVantage Rescue and Recovery package. It comes with a
&lt;br&gt;TVT packet filter tvtpktfilter.sys), which have some problems with the NSR
&lt;br&gt;client.
&lt;br&gt;Juniper KB article: &lt;a href=&quot;http://kb.juniper.net/KB9275&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://kb.juniper.net/KB9275&lt;/a&gt;&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;Eszter
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; given a new lenovo T60 with Windows XP Service Pack 2. The machine
&lt;br&gt;&amp;gt; came with &amp;quot;Symantec Client Security&amp;quot; pre-installed, which was removed
&lt;br&gt;&amp;gt; before trying to install the NSR Client.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Upon installation of the NSR Client (1.3.5 Build 6), the box
&lt;br&gt;&amp;gt; bluescreens with &amp;quot;BAD_POOL_CALLER&amp;quot; and the STOP data
&lt;br&gt;&amp;gt; STOP 0x000000C2 (0x0000007,0x00000cd4,0x23c0000,0x85ae008).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; What might be going wrong here?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Greetings
&lt;br&gt;&amp;gt; Marc
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; -----------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Marc Haber &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;I don't trust Computers. They | Mailadresse im
&lt;br&gt;&amp;gt; Header
&lt;br&gt;&amp;gt; Mannheim, Germany &amp;nbsp;| &amp;nbsp;lose things.&amp;quot; &amp;nbsp; &amp;nbsp;Winona Ryder | Fon: *49 621
&lt;br&gt;&amp;gt; 72739834
&lt;br&gt;&amp;gt; Nordisch by Nature | &amp;nbsp;How to make an American Quilt | Fax: *49 621
&lt;br&gt;&amp;gt; 72739835
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; nn mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9728421&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9728421&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/NSR-Client-10.3.5-blue-screening-on-installation-tp9716314p9728421.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9719064</id>
	<title>Re: Nsrp question</title>
	<published>2007-03-28T11:22:03Z</published>
	<updated>2007-03-28T11:22:03Z</updated>
	<author>
		<name>Tim E</name>
	</author>
	<content type="html">And no, it will not be replicated to the second member.&lt;br&gt;&lt;br&gt;Incase you were wondering.. To bring the underface back up:&lt;br&gt;&lt;br&gt;unset int x/x phy link-down&lt;br&gt;&lt;br&gt;-Tim Eberhard&lt;br&gt;&lt;br&gt;&lt;div&gt;&lt;span class=&quot;gmail_quote&quot;&gt;On 3/26/07, 
&lt;b class=&quot;gmail_sendername&quot;&gt;Arno MESGUICH&lt;/b&gt; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9719064&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;arno.mesguich@...&lt;/a&gt;&amp;gt; wrote:&lt;/span&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;




&lt;div&gt;
&lt;div&gt;&lt;span&gt;&lt;font face=&quot;Century Gothic&quot; size=&quot;2&quot;&gt;Hi 
all,&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;font face=&quot;Century Gothic&quot; size=&quot;2&quot;&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;font face=&quot;Century Gothic&quot; size=&quot;2&quot;&gt;i have a 
nsrp cluster with 2 members. All interfaces are monitored, and if one interface 
is lost, it fails over.&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;font face=&quot;Century Gothic&quot; size=&quot;2&quot;&gt;I shut an 
interface down on first member using CLI : set i e1/1 link-phys 
down&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;font face=&quot;Century Gothic&quot; size=&quot;2&quot;&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;font face=&quot;Century Gothic&quot; size=&quot;2&quot;&gt;Is it 
replicated on the second member ?&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;font face=&quot;Century Gothic&quot; size=&quot;2&quot;&gt;Does the 
cluster fail over ?(does the second member become active ?)&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;font face=&quot;Century Gothic&quot; size=&quot;2&quot;&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;font face=&quot;Century Gothic&quot; size=&quot;2&quot;&gt;Thanks 
for your help.&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div align=&quot;left&quot;&gt;
&lt;table align=&quot;left&quot; border=&quot;0&quot; height=&quot;87&quot; width=&quot;240&quot;&gt;
  &lt;tbody&gt;
  &lt;tr&gt;
    &lt;td scope=&quot;col&quot; align=&quot;left&quot; valign=&quot;top&quot;&gt;
      &lt;div style=&quot;font-size: 9pt; color: rgb(51, 51, 51); font-family: Arial;&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Arno Mesguich&lt;/strong&gt;&lt;br&gt;Security Engineer&lt;br&gt;Service 
      : technique&lt;br&gt;Email : &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9719064&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;arno.mesguich@...&lt;/a&gt;&lt;br&gt;Tél : +33 
      (0)1 41 85 10 30&lt;br&gt;Fax : +33 (0)1 41 85 10 21&lt;br&gt;
      &lt;p&gt;&lt;a href=&quot;http://www.noxs.fr/services/partner-services/xteam-request/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;http://www.nabble.com/attachment/9719064/0/attf149c.gif&quot; border=&quot;0&quot; height=&quot;50&quot; width=&quot;180&quot;&gt;
&lt;br&gt;Besoin de ressources techniques ? &lt;/a&gt;&lt;/p&gt;&lt;br&gt;&lt;strong&gt;NOXS 
      France&lt;/strong&gt;&lt;br&gt;9 - 11 Allée des Pierres Mayettes&lt;br&gt;92632 
      GENNEVILLIERS Cedex&lt;br&gt;Web : &lt;a href=&quot;http://www.noxs.fr/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.noxs.fr&lt;/a&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
  &lt;tr&gt;
    &lt;td scope=&quot;row&quot; align=&quot;left&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
  &lt;tr&gt;
    &lt;td scope=&quot;row&quot; align=&quot;left&quot;&gt;&lt;a href=&quot;http://www.noxs.fr/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;&lt;img src=&quot;http://www.nabble.com/attachment/9719064/1/attf149d.gif&quot; border=&quot;0&quot; height=&quot;44&quot; width=&quot;150&quot;&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;/div&gt;
&lt;br&gt;_______________________________________________&lt;br&gt;nn mailing list&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9719064&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;
http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt; &lt;br /&gt; &lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9719064&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Nsrp-question-tp9672497p9719064.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9717194</id>
	<title>Re: Nsrp question</title>
	<published>2007-03-28T09:45:22Z</published>
	<updated>2007-03-28T09:45:22Z</updated>
	<author>
		<name>dh-7</name>
	</author>
	<content type="html">Yes, it will initiate a failover, and the command is:
&lt;br&gt;set int x/x phy link-down
&lt;br&gt;&lt;br&gt;/dh
&lt;br&gt;&lt;br&gt;&lt;br&gt;Arno MESGUICH wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; i have a nsrp cluster with 2 members. All interfaces are monitored, 
&lt;br&gt;&amp;gt; and if one interface is lost, it fails over.
&lt;br&gt;&amp;gt; I shut an interface down on first member using CLI : set i e1/1 
&lt;br&gt;&amp;gt; link-phys down
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; Is it replicated on the second member ?
&lt;br&gt;&amp;gt; Does the cluster fail over ?(does the second member become active ?)
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; Thanks for your help.
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; *Arno Mesguich*
&lt;br&gt;&amp;gt; Security Engineer
&lt;br&gt;&amp;gt; Service : technique
&lt;br&gt;&amp;gt; Email : &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9717194&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;arno.mesguich@...&lt;/a&gt; &amp;lt;mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9717194&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;arno.mesguich@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Tél : +33 (0)1 41 85 10 30
&lt;br&gt;&amp;gt; Fax : +33 (0)1 41 85 10 21
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Besoin de ressources techniques ? 
&lt;br&gt;&amp;gt; &amp;lt;&lt;a href=&quot;http://www.noxs.fr/services/partner-services/xteam-request/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.noxs.fr/services/partner-services/xteam-request/&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; *NOXS France*
&lt;br&gt;&amp;gt; 9 - 11 Allée des Pierres Mayettes
&lt;br&gt;&amp;gt; 92632 GENNEVILLIERS Cedex
&lt;br&gt;&amp;gt; Web : &lt;a href=&quot;http://www.noxs.fr&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.noxs.fr&lt;/a&gt;&amp;nbsp;&amp;lt;&lt;a href=&quot;http://www.noxs.fr/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.noxs.fr/&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;lt;&lt;a href=&quot;http://www.noxs.fr/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.noxs.fr/&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; nn mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9717194&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9717194&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Nsrp-question-tp9672497p9717194.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9716314</id>
	<title>NSR Client 10.3.5 blue screening on installation</title>
	<published>2007-03-28T09:06:09Z</published>
	<updated>2007-03-28T09:06:09Z</updated>
	<author>
		<name>Marc Haber-6</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;given a new lenovo T60 with Windows XP Service Pack 2. The machine
&lt;br&gt;came with &amp;quot;Symantec Client Security&amp;quot; pre-installed, which was removed
&lt;br&gt;before trying to install the NSR Client.
&lt;br&gt;&lt;br&gt;Upon installation of the NSR Client (1.3.5 Build 6), the box
&lt;br&gt;bluescreens with &amp;quot;BAD_POOL_CALLER&amp;quot; and the STOP data
&lt;br&gt;STOP 0x000000C2 (0x0000007,0x00000cd4,0x23c0000,0x85ae008).
&lt;br&gt;&lt;br&gt;What might be going wrong here?
&lt;br&gt;&lt;br&gt;Greetings
&lt;br&gt;Marc
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;-----------------------------------------------------------------------------
&lt;br&gt;Marc Haber &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;I don't trust Computers. They | Mailadresse im Header
&lt;br&gt;Mannheim, Germany &amp;nbsp;| &amp;nbsp;lose things.&amp;quot; &amp;nbsp; &amp;nbsp;Winona Ryder | Fon: *49 621 72739834
&lt;br&gt;Nordisch by Nature | &amp;nbsp;How to make an American Quilt | Fax: *49 621 72739835
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9716314&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/NSR-Client-10.3.5-blue-screening-on-installation-tp9716314p9716314.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9715839</id>
	<title>Re: How to reduce MTU for a VPN tunnel?</title>
	<published>2007-03-28T08:44:38Z</published>
	<updated>2007-03-28T08:44:38Z</updated>
	<author>
		<name>Tim E</name>
	</author>
	<content type="html">In the event of the MTU setting not showing up, that means it&amp;#39;s set for the default setting 1514. Sometimes it shows up when it&amp;#39;s set for default, sometimes it doesn&amp;#39;t. It varies from code to code and on different platforms.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;div&gt;&lt;span class=&quot;gmail_quote&quot;&gt;On 3/28/07, &lt;b class=&quot;gmail_sendername&quot;&gt;STEVE KNAPP&lt;/b&gt; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9715839&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;SKNAPP@...&lt;/a&gt;&amp;gt; wrote:&lt;/span&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;



&lt;div style=&quot;margin: 4px 4px 1px; font-family: Tahoma; font-style: normal; font-variant: normal; font-weight: normal; font-size: 10pt; line-height: normal; font-size-adjust: none; font-stretch: normal;&quot;&gt;
&lt;div&gt;Does anyone know if there is a different command on an ISG-2000?&amp;nbsp; When I run &amp;#39;get envar&amp;#39;&amp;nbsp;the MTU size is not returned.&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;spefwfi100(M)-&amp;gt; get envar&lt;br&gt;default_image=nsISG2000.5.0.0r8.2&lt;br&gt;run_image=default (nsISG2000.5.0.0r8.2)&lt;br&gt;loader_version=1.1.5&lt;br&gt;last_reset=2006-12-20 21:46:47 by admin&lt;br&gt;.hash-seg=11 (507713657)&lt;br&gt;sme= &lt;/div&gt;

&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;Steve Knapp&lt;br&gt;Sr. Data Network Engineer&lt;br&gt;Sallie Mae&lt;br&gt;11100 USA Parkway&lt;br&gt;Fishers, IN 46038&lt;br&gt;Tel:&amp;nbsp; 317-578-6799&lt;br&gt;Cell: 317-847-9221&lt;br&gt;Fax: 317-595-1494&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;quot;Tim Eberhard&amp;quot; &amp;lt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9715839&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;xmin0s@...&lt;/a&gt;&amp;gt; 3/27/2007 2:58 PM &amp;gt;&amp;gt;&amp;gt;&lt;div&gt;&lt;span class=&quot;e&quot; id=&quot;q_111988b63105b340_1&quot;&gt;&lt;br&gt;Marc,&lt;br&gt;&lt;br&gt;
The MTU setting is a system wide configuration. To view this use the &amp;quot;get envar&amp;quot; command.&lt;br&gt;&lt;br&gt;netscreen(M)-&amp;gt; get envar&lt;br&gt;&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; redirect output show resource variable&lt;br&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; match output 
&lt;br&gt;&lt;br&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br&gt;netscreen(M)-&amp;gt; get envar&lt;br&gt;default_image=ns5000.5.0.0&lt;br&gt;run_image=default (ns5000.5.0.0)&lt;br&gt;loader_version=1.0.0&lt;br&gt;last_reset=2006-11-11 13:44:12 by netscreen&lt;br&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;
max-frame-size=9830&lt;/span&gt;&lt;br&gt;&lt;br&gt;The example above is a jumbo configuration. Normally the max-frame size should be 1514. To adjust the MTU you use the following command:&lt;br&gt;&lt;br&gt;set envar max-frame-size=1514&lt;br&gt;&lt;br&gt;That would change this to 1514. If you want to go smaller..that is how you would do it. 
&lt;br&gt;&lt;br&gt;Good luck!&lt;br&gt;&lt;br&gt;Tim Eberhard&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;span class=&quot;e&quot; id=&quot;q_111988b63105b340_3&quot;&gt;
&lt;div&gt;&lt;span class=&quot;gmail_quote&quot;&gt;On 3/27/07, &lt;b class=&quot;gmail_sendername&quot;&gt;Marc Haber&lt;/b&gt; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9715839&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mh+qorbit-nn@...&lt;/a&gt;&amp;gt; wrote: &lt;/span&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;On Tue, Mar 27, 2007 at 06:53:39AM -0800, Matt Florido wrote:&lt;br&gt;&amp;gt; * Marc Haber &amp;lt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9715839&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mh+qorbit-nn@...&lt;/a&gt;&amp;gt; [03-23-2007 19:18]:&lt;br&gt;&amp;gt; &amp;gt; (2) How can I for testing purposes reduce the MTU the NSR client uses&lt;br&gt;&amp;gt; &amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; for data sent into the VPN tunnel? Setting the appropriate registry 
&lt;br&gt;&amp;gt; &amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; key on the virtual ethernet adapter does not work; the setting is&lt;br&gt;&amp;gt; &amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; simply igored (verified by ping with a big request packet)&lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt; Try setting the MTU setting on the network adapter itself instead 
&lt;br&gt;&amp;gt; of the virtual adapter for NSR.&lt;br&gt;&lt;br&gt;This does not help since the Tunnel&amp;#39;s MTU is always smaller than the&lt;br&gt;MTU of the physical network.&lt;br&gt;&lt;br&gt;&amp;gt; &amp;gt; (3) Why do such MTU issues only surface with one application? 
&lt;br&gt;&amp;gt; &amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Everything else seems to be just fine.&lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt; You have only found it in one application, but I&amp;#39;ve found the issue&lt;br&gt;&amp;gt; manifests itself when applications like using max packet sizes.&lt;br&gt;&lt;br&gt;
Both E-Mail (Exchange, Outlook, *blech*) and network shares work fine&lt;br&gt;even when data sizes well beyond the network MTU are in use.&lt;br&gt;&lt;br&gt;&amp;gt; Here&amp;#39;s something to try.&amp;nbsp;&amp;nbsp;Adjust the TCP MSS settings on your NS5GT.&lt;br&gt;
&amp;gt;&lt;br&gt;&amp;gt; set flow tcp-mss xxx (1300 is a good number to test with)&lt;br&gt;&amp;gt; set flow all-tcp-mss xxx (1400)&lt;br&gt;&lt;br&gt;This seems to work fine:&lt;br&gt;&lt;br&gt;ns5gt-&amp;gt; get config | include mss&lt;br&gt;set flow tcp-mss 1100&lt;br&gt;set flow all-tcp-mss 1200 
&lt;br&gt;ns5gt-&amp;gt; exit&lt;br&gt;&lt;br&gt;19:17:04.306354 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: S 1765254697:1765254697(0) win 16384 &amp;lt;mss 1200,nop,nop,sackOK&amp;gt;&lt;br&gt;19:17:04.306590 IP 10.1.2.92.10000 &amp;gt; 10.2.90.51.1299: S 3882353262:3882353262(0) ack 1765254698 win 5840 &amp;lt;mss 1460,nop,nop,sackOK&amp;gt; 
&lt;br&gt;19:17:04.308102 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: . ack 1 win 16500&lt;br&gt;19:17:04.317237 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: . 1:1101(1100) ack 1 win 16500&lt;br&gt;19:17:04.317653 IP 10.1.2.92.10000 &amp;gt; 10.2.90.51.1299
 : . ack 1101 win 7700&lt;br&gt;19:17:04.318235 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: . 1101:2201(1100) ack 1 win 16500&lt;br&gt;19:17:04.318651 IP 10.1.2.92.10000 &amp;gt; 10.2.90.51.1299: . ack 2201 win 9900&lt;br&gt;19:17:04.320681 IP 10.2.90.51.1299
 &amp;gt; 10.1.2.92.10000: . 2201:3301(1100) ack 1 win 16500&lt;br&gt;19:17:04.321095 IP 10.1.2.92.10000 &amp;gt; 10.2.90.51.1299: . ack 3301 win 12100&lt;br&gt;19:17:04.323427 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: . 3301:4401(1100) ack 1 win 16500 
&lt;br&gt;19:17:04.323530 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: . 4401:5501(1100) ack 1 win 16500&lt;br&gt;19:17:04.323628 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: . 5501:6601(1100) ack 1 win 16500&lt;br&gt;&lt;br&gt;(&lt;a href=&quot;http://10.2.90.51/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;
 10.2.90.51&lt;/a&gt; is the virtual IP of the client, &lt;a href=&quot;http://10.1.2.92/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.1.2.92&lt;/a&gt; the address of&lt;br&gt;the &amp;quot;test server&amp;quot;).&lt;br&gt;&lt;br&gt;However, Microsoft Office Communicator still refuses to work:
&lt;br&gt;19:19:31.693440 IP 10.2.90.51.1324 &amp;gt; 10.1.2.15.5060: S 214820639:214820639(0) win 16384 &amp;lt;mss 1200,nop,nop,sackOK&amp;gt;&lt;br&gt;19:19:31.693576 IP 10.1.2.15.5060 &amp;gt; 10.2.90.51.1324: S 2055039840:2055039840(0) ack 214820640 win 16384 &amp;lt;mss 1460,nop,nop,sackOK&amp;gt; 
&lt;br&gt;19:19:31.695100 IP 10.2.90.51.1324 &amp;gt; 10.1.2.15.5060: . ack 1 win 16500&lt;br&gt;19:19:31.695456 IP 10.1.2.15.5060 &amp;gt; 10.2.90.51.1301: R 3947954180:3947954180(0) ack 3726277644 win 0&lt;br&gt;19:19:31.751359 IP 10.2.90.51.1324
 &amp;gt; 10.1.2.15.5060: P 1:660(659) ack 1 win 16500&lt;br&gt;19:19:31.751748 IP 10.1.2.15.5060 &amp;gt; 10.2.90.51.1324: P 1:561(560) ack 660 win 64876&lt;br&gt;19:19:34.706224 IP 10.1.2.15.5060 &amp;gt; 10.2.90.51.1324: P 1:561(560) ack 660 win 64876 
&lt;br&gt;19:19:34.710886 IP 10.2.90.51.1324 &amp;gt; 10.1.2.15.5060: . ack 561 win 15940&lt;br&gt;&lt;br&gt;(&lt;a href=&quot;http://10.1.2.15/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;10.1.2.15&lt;/a&gt; is the MOC Server)&lt;br&gt;
&lt;br&gt;When I compare the session setup when the client is not connecting &lt;br&gt;over the VPN to this, I see that the VPN connect stalls when the&lt;br&gt;non-VPN connect begins transmitting datagrams of like 1360 bytes in&lt;br&gt;size.&lt;br&gt;
&lt;br&gt;Any more ideas?&lt;br&gt;&lt;br&gt;Greetings&lt;br&gt;Marc&lt;br&gt;&lt;br&gt;--&lt;br&gt;----------------------------------------------------------------------------- &lt;br&gt;Marc Haber&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | &amp;quot;I don&amp;#39;t trust Computers. They | Mailadresse im Header
&lt;br&gt;Mannheim, Germany&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;lose things.&amp;quot;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Winona Ryder | Fon: *49 621 72739834&lt;br&gt;Nordisch by Nature |&amp;nbsp;&amp;nbsp;How to make an American Quilt | Fax: *49 621 72739835 &lt;br&gt;_______________________________________________&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9715839&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;
http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;/span&gt;&lt;/div&gt;This E-Mail has been scanned for viruses.&lt;br&gt;&lt;/div&gt;
&lt;br&gt;_______________________________________________&lt;br&gt;nn mailing list&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9715839&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;
http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9715839&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-reduce-MTU-for-a-VPN-tunnel--tp9641863p9715839.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9712890</id>
	<title>Re: How to reduce MTU for a VPN tunnel?</title>
	<published>2007-03-28T05:58:10Z</published>
	<updated>2007-03-28T05:58:10Z</updated>
	<author>
		<name>STEVE KNAPP</name>
	</author>
	<content type="html">&lt;HTML&gt;&lt;HEAD&gt;
&lt;META http-equiv=Content-Type content=&quot;text/html; charset=iso-8859-15&quot;&gt;
&lt;META content=&quot;MSHTML 6.00.2900.3020&quot; name=GENERATOR&gt;&lt;/HEAD&gt;
&lt;BODY style=&quot;MARGIN: 4px 4px 1px; FONT: 10pt Tahoma&quot;&gt;
&lt;DIV&gt;Does anyone know if there is a different command on an ISG-2000?&amp;nbsp; When I run 'get envar'&amp;nbsp;the MTU size is not returned.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;spefwfi100(M)-&amp;gt; get envar&lt;BR&gt;default_image=nsISG2000.5.0.0r8.2&lt;BR&gt;run_image=default (nsISG2000.5.0.0r8.2)&lt;BR&gt;loader_version=1.1.5&lt;BR&gt;last_reset=2006-12-20 21:46:47 by admin&lt;BR&gt;.hash-seg=11 (507713657)&lt;BR&gt;sme= &lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Steve Knapp&lt;BR&gt;Sr. Data Network Engineer&lt;BR&gt;Sallie Mae&lt;BR&gt;11100 USA Parkway&lt;BR&gt;Fishers, IN 46038&lt;BR&gt;Tel:&amp;nbsp; 317-578-6799&lt;BR&gt;Cell: 317-847-9221&lt;BR&gt;Fax: 317-595-1494&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&amp;gt;&amp;gt;&amp;gt; &quot;Tim Eberhard&quot; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9712890&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;xmin0s@...&lt;/a&gt;&amp;gt; 3/27/2007 2:58 PM &amp;gt;&amp;gt;&amp;gt;&lt;BR&gt;Marc,&lt;BR&gt;&lt;BR&gt;The MTU setting is a system wide configuration. To view this use the &quot;get envar&quot; command.&lt;BR&gt;&lt;BR&gt;netscreen(M)-&amp;gt; get envar&lt;BR&gt;&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; redirect output show resource variable&lt;BR&gt;|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; match output &lt;BR&gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR&gt;netscreen(M)-&amp;gt; get envar&lt;BR&gt;default_image=ns5000.5.0.0&lt;BR&gt;run_image=default (ns5000.5.0.0)&lt;BR&gt;loader_version=1.0.0&lt;BR&gt;last_reset=2006-11-11 13:44:12 by netscreen&lt;BR&gt;&lt;SPAN style=&quot;FONT-WEIGHT: bold&quot;&gt;max-frame-size=9830&lt;/SPAN&gt;&lt;BR&gt;&lt;BR&gt;The example above is a jumbo configuration. Normally the max-frame size should be 1514. To adjust the MTU you use the following command:&lt;BR&gt;&lt;BR&gt;set envar max-frame-size=1514&lt;BR&gt;&lt;BR&gt;That would change this to 1514. If you want to go smaller..that is how you would do it. &lt;BR&gt;&lt;BR&gt;Good luck!&lt;BR&gt;&lt;BR&gt;Tim Eberhard&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=gmail_quote&gt;On 3/27/07, &lt;B class=gmail_sendername&gt;Marc Haber&lt;/B&gt; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9712890&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mh+qorbit-nn@...&lt;/a&gt;&amp;gt; wrote: &lt;/SPAN&gt;
&lt;BLOCKQUOTE class=gmail_quote style=&quot;PADDING-LEFT: 1ex; MARGIN: 0pt 0pt 0pt 0.8ex; BORDER-LEFT: rgb(204,204,204) 1px solid&quot;&gt;On Tue, Mar 27, 2007 at 06:53:39AM -0800, Matt Florido wrote:&lt;BR&gt;&amp;gt; * Marc Haber &amp;lt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9712890&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mh+qorbit-nn@...&lt;/a&gt;&amp;gt; [03-23-2007 19:18]:&lt;BR&gt;&amp;gt; &amp;gt; (2) How can I for testing purposes reduce the MTU the NSR client uses&lt;BR&gt;&amp;gt; &amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; for data sent into the VPN tunnel? Setting the appropriate registry &lt;BR&gt;&amp;gt; &amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; key on the virtual ethernet adapter does not work; the setting is&lt;BR&gt;&amp;gt; &amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; simply igored (verified by ping with a big request packet)&lt;BR&gt;&amp;gt;&lt;BR&gt;&amp;gt; Try setting the MTU setting on the network adapter itself instead &lt;BR&gt;&amp;gt; of the virtual adapter for NSR.&lt;BR&gt;&lt;BR&gt;This does not help since the Tunnel's MTU is always smaller than the&lt;BR&gt;MTU of the physical network.&lt;BR&gt;&lt;BR&gt;&amp;gt; &amp;gt; (3) Why do such MTU issues only surface with one application? &lt;BR&gt;&amp;gt; &amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Everything else seems to be just fine.&lt;BR&gt;&amp;gt;&lt;BR&gt;&amp;gt; You have only found it in one application, but I've found the issue&lt;BR&gt;&amp;gt; manifests itself when applications like using max packet sizes.&lt;BR&gt;&lt;BR&gt;Both E-Mail (Exchange, Outlook, *blech*) and network shares work fine&lt;BR&gt;even when data sizes well beyond the network MTU are in use.&lt;BR&gt;&lt;BR&gt;&amp;gt; Here's something to try.&amp;nbsp;&amp;nbsp;Adjust the TCP MSS settings on your NS5GT.&lt;BR&gt;&amp;gt;&lt;BR&gt;&amp;gt; set flow tcp-mss xxx (1300 is a good number to test with)&lt;BR&gt;&amp;gt; set flow all-tcp-mss xxx (1400)&lt;BR&gt;&lt;BR&gt;This seems to work fine:&lt;BR&gt;&lt;BR&gt;ns5gt-&amp;gt; get config | include mss&lt;BR&gt;set flow tcp-mss 1100&lt;BR&gt;set flow all-tcp-mss 1200 &lt;BR&gt;ns5gt-&amp;gt; exit&lt;BR&gt;&lt;BR&gt;19:17:04.306354 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: S 1765254697:1765254697(0) win 16384 &amp;lt;mss 1200,nop,nop,sackOK&amp;gt;&lt;BR&gt;19:17:04.306590 IP 10.1.2.92.10000 &amp;gt; 10.2.90.51.1299: S 3882353262:3882353262(0) ack 1765254698 win 5840 &amp;lt;mss 1460,nop,nop,sackOK&amp;gt; &lt;BR&gt;19:17:04.308102 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: . ack 1 win 16500&lt;BR&gt;19:17:04.317237 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: . 1:1101(1100) ack 1 win 16500&lt;BR&gt;19:17:04.317653 IP 10.1.2.92.10000 &amp;gt; 10.2.90.51.1299 : . ack 1101 win 7700&lt;BR&gt;19:17:04.318235 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: . 1101:2201(1100) ack 1 win 16500&lt;BR&gt;19:17:04.318651 IP 10.1.2.92.10000 &amp;gt; 10.2.90.51.1299: . ack 2201 win 9900&lt;BR&gt;19:17:04.320681 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: . 2201:3301(1100) ack 1 win 16500&lt;BR&gt;19:17:04.321095 IP 10.1.2.92.10000 &amp;gt; 10.2.90.51.1299: . ack 3301 win 12100&lt;BR&gt;19:17:04.323427 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: . 3301:4401(1100) ack 1 win 16500 &lt;BR&gt;19:17:04.323530 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: . 4401:5501(1100) ack 1 win 16500&lt;BR&gt;19:17:04.323628 IP 10.2.90.51.1299 &amp;gt; 10.1.2.92.10000: . 5501:6601(1100) ack 1 win 16500&lt;BR&gt;&lt;BR&gt;(&lt;A href=&quot;http://10.2.90.51/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt; 10.2.90.51&lt;/A&gt; is the virtual IP of the client, &lt;A href=&quot;http://10.1.2.92/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;10.1.2.92&lt;/A&gt; the address of&lt;BR&gt;the &quot;test server&quot;).&lt;BR&gt;&lt;BR&gt;However, Microsoft Office Communicator still refuses to work:&lt;BR&gt;19:19:31.693440 IP 10.2.90.51.1324 &amp;gt; 10.1.2.15.5060: S 214820639:214820639(0) win 16384 &amp;lt;mss 1200,nop,nop,sackOK&amp;gt;&lt;BR&gt;19:19:31.693576 IP 10.1.2.15.5060 &amp;gt; 10.2.90.51.1324: S 2055039840:2055039840(0) ack 214820640 win 16384 &amp;lt;mss 1460,nop,nop,sackOK&amp;gt; &lt;BR&gt;19:19:31.695100 IP 10.2.90.51.1324 &amp;gt; 10.1.2.15.5060: . ack 1 win 16500&lt;BR&gt;19:19:31.695456 IP 10.1.2.15.5060 &amp;gt; 10.2.90.51.1301: R 3947954180:3947954180(0) ack 3726277644 win 0&lt;BR&gt;19:19:31.751359 IP 10.2.90.51.1324 &amp;gt; 10.1.2.15.5060: P 1:660(659) ack 1 win 16500&lt;BR&gt;19:19:31.751748 IP 10.1.2.15.5060 &amp;gt; 10.2.90.51.1324: P 1:561(560) ack 660 win 64876&lt;BR&gt;19:19:34.706224 IP 10.1.2.15.5060 &amp;gt; 10.2.90.51.1324: P 1:561(560) ack 660 win 64876 &lt;BR&gt;19:19:34.710886 IP 10.2.90.51.1324 &amp;gt; 10.1.2.15.5060: . ack 561 win 15940&lt;BR&gt;&lt;BR&gt;(&lt;A href=&quot;http://10.1.2.15/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;10.1.2.15&lt;/A&gt; is the MOC Server)&lt;BR&gt;&lt;BR&gt;When I compare the session setup when the client is not connecting &lt;BR&gt;over the VPN to this, I see that the VPN connect stalls when the&lt;BR&gt;non-VPN connect begins transmitting datagrams of like 1360 bytes in&lt;BR&gt;size.&lt;BR&gt;&lt;BR&gt;Any more ideas?&lt;BR&gt;&lt;BR&gt;Greetings&lt;BR&gt;Marc&lt;BR&gt;&lt;BR&gt;--&lt;BR&gt;----------------------------------------------------------------------------- &lt;BR&gt;Marc Haber&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | &quot;I don't trust Computers. They | Mailadresse im Header&lt;BR&gt;Mannheim, Germany&amp;nbsp;&amp;nbsp;|&amp;nbsp;&amp;nbsp;lose things.&quot;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Winona Ryder | Fon: *49 621 72739834&lt;BR&gt;Nordisch by Nature |&amp;nbsp;&amp;nbsp;How to make an American Quilt | Fax: *49 621 72739835 &lt;BR&gt;_______________________________________________&lt;BR&gt;nn mailing list&lt;BR&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9712890&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;&lt;BR&gt;&lt;A href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/A&gt;&lt;BR&gt;&lt;/BLOCKQUOTE&gt;&lt;/DIV&gt;&lt;BR&gt;&lt;BR&gt;This E-Mail has been scanned for viruses.&lt;BR&gt;&lt;/BODY&gt;&lt;/HTML&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9712890&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-reduce-MTU-for-a-VPN-tunnel--tp9641863p9712890.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9702929</id>
	<title>New mailing list domain</title>
	<published>2007-03-27T16:45:58Z</published>
	<updated>2007-03-27T16:45:58Z</updated>
	<author>
		<name>Stephen Gill</name>
	</author>
	<content type="html">Dear NN users,
&lt;br&gt;&lt;br&gt;Due to a changing personal focus we will be migrating this list over to a
&lt;br&gt;new server, managed and run by David Burke (&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9702929&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;dave@...&lt;/a&gt;). &amp;nbsp; You can
&lt;br&gt;find the main list page here:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.compsoc.com/cgi-bin/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;&lt;br&gt;I will soon be adding a 302 redirect from the current web page to
&lt;br&gt;compsoc.com. &amp;nbsp;To post to the new list, simply send a note to:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9702929&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;All of your existing subscriptions have been transferred to the new domain.
&lt;br&gt;If for some reason you'd like to unsubscribe please feel free to contact
&lt;br&gt;David Burke directly or use the interface at the URL above. &amp;nbsp;Please feel
&lt;br&gt;free to contact me with any questions about the move.
&lt;br&gt;&lt;br&gt;Please adjust your whitelists accordingly. &amp;nbsp;David will send an e-mail from
&lt;br&gt;the new domain as a test.
&lt;br&gt;&lt;br&gt;There isn't yet an archive search function but he is working on it, and
&lt;br&gt;should have something before too long.
&lt;br&gt;&lt;br&gt;Many thanks!
&lt;br&gt;&lt;br&gt;-- steve
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=9702929&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nn@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/New-mailing-list-domain-tp9702929p9702929.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9700238</id>
	<title>Re: SOHO Security Products</title>
	<published>2007-03-27T14:21:40Z</published>
	<updated>2007-03-27T14:21:40Z</updated>
	<author>
		<name>Joekim13</name>
	</author>
	<content type="html">basically cost and # of internal(trust users). HSC can have a max of 5 ip addresses so suitable for a few pcs'.
&lt;br&gt;&lt;br&gt;Joe
&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;Nathan C. Smith wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Can anyone comment on the differences between a 5XT/GT and an HSC? &amp;nbsp;How
&lt;br&gt;would you determine suitability of one or the other for a particular
&lt;br&gt;application?
&lt;br&gt;&lt;br&gt;Thanks.
&lt;br&gt;&lt;br&gt;-Nate
&lt;br&gt;&lt;br&gt;Nathan Smith &amp;nbsp;McKee, Voorhees &amp; Sease, P.L.C.
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;nn@qorbit.net
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SOHO-Security-Products-tp9086894p9700238.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9700236</id>
	<title>Re: Group IKE id issue</title>
	<published>2007-03-27T14:18:38Z</published>
	<updated>2007-03-27T14:18:38Z</updated>
	<author>
		<name>Joekim13</name>
	</author>
	<content type="html">you might need to remove all he assoications or unconfigure the groupike ike out of the current vpn.
&lt;br&gt;&lt;br&gt;Joe
&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;Øyvind Mattland wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Hello, do anyone know how you can remove a user that has been generated by this command: ?
&lt;br&gt;&amp;nbsp;
&lt;br&gt;exec ike preshare-gen corp_gw user@corp.com
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Thanks
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Med vennlig hilsen/Best regards,
&lt;br&gt;&lt;br&gt;&amp;gt; Øyvind Mattland
&lt;br&gt;&lt;br&gt;Network Security Engineer
&lt;br&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;nn@qorbit.net
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Group-IKE-id-issue-tp9178795p9700236.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9700146</id>
	<title>Re: How to reduce MTU for a VPN tunnel?</title>
	<published>2007-03-27T14:12:40Z</published>
	<updated>2007-03-27T14:12:40Z</updated>
	<author>
		<name>Joekim13</name>
	</author>
	<content type="html">I didn't see you already tried adjusting MSS.
&lt;br&gt;&lt;br&gt;Try upgrading to 5.4r3. I've had something similar.
&lt;br&gt;&lt;br&gt;Joe
&lt;br&gt;&lt;quote author='Joekim13'&gt;&lt;br&gt;Which hardware are you using? if its an asic based such as ISG2k or NS5200 and your using Vsys or vlans try 5.4r3.
&lt;br&gt;&lt;br&gt;Also you can try adjusting MSS values.
&lt;br&gt;&lt;br&gt;set flow tcp mss 1400(default) try lowering to 1200.
&lt;br&gt;and 
&lt;br&gt;set flow max-frag-pkt-size (60 bytes less than mss)
&lt;br&gt;&lt;br&gt;&lt;br&gt;Joe
&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;Marc Haber-6 wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Hi,
&lt;br&gt;&lt;br&gt;I am having issues with Windows clients using Microsoft Office
&lt;br&gt;Communicator through an NSR VPN. Client is Windows XP SP2 with NSR
&lt;br&gt;Client 10.3.5 (Build 6). I suspect this is an MTU issue.
&lt;br&gt;&lt;br&gt;When the Client is accessing the Live Communication Server directly,
&lt;br&gt;everything is fine:
&lt;br&gt;&lt;br&gt;18:51:39.770881 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: S 1182056209:1182056209(0) win 65535 &amp;lt;mss 1380,nop,nop,sackOK&amp;gt;
&lt;br&gt;18:51:39.770990 IP 10.1.2.15.5060 &amp;gt; 10.2.203.101.2247: S 689666419:689666419(0) ack 1182056210 win 16384 &amp;lt;mss 1460,nop,nop,sackOK&amp;gt;
&lt;br&gt;18:51:39.771223 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: . ack 1 win 65535
&lt;br&gt;18:51:39.774990 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: P 1:662(661) ack 1 win 65535
&lt;br&gt;18:51:39.775340 IP 10.1.2.15.5060 &amp;gt; 10.2.203.101.2247: P 1:562(561) ack 662 win 64874
&lt;br&gt;18:51:39.834843 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: . 662:2042(1380) ack 562 win 64974
&lt;br&gt;18:51:39.834956 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: . 2042:3422(1380) ack 562 win 64974
&lt;br&gt;18:51:39.835055 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: . 3422:4802(1380) ack 562 win 64974
&lt;br&gt;18:51:39.835123 IP 10.1.2.15.5060 &amp;gt; 10.2.203.101.2247: . ack 3422 win 65535
&lt;br&gt;18:51:39.835243 IP 10.1.2.15.5060 &amp;gt; 10.2.203.101.2247: . ack 4802 win 65535
&lt;br&gt;18:51:39.835501 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: . 4802:6182(1380) ack 562 win 64974
&lt;br&gt;18:51:39.835547 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: P 6182:6877(695) ack 562 win 64974
&lt;br&gt;&lt;br&gt;We see the 3-way handshake, then two small packets, and then packets
&lt;br&gt;in the size range of the network MTU.
&lt;br&gt;&lt;br&gt;When the Client is going through the VPN, things go wrong badly:
&lt;br&gt;&lt;br&gt;18:53:44.028012 IP 10.2.90.44.2270 &amp;gt; 10.1.2.15.5060: S 3728511120:3728511120(0) win 16384 &amp;lt;mss 1280,nop,nop,sackOK&amp;gt;
&lt;br&gt;18:53:44.028108 IP 10.1.2.15.5060 &amp;gt; 10.2.90.44.2270: S 2496991569:2496991569(0) ack 3728511121 win 16384 &amp;lt;mss 1460,nop,nop,sackOK&amp;gt;
&lt;br&gt;18:53:44.029649 IP 10.2.90.44.2270 &amp;gt; 10.1.2.15.5060: . ack 1 win 16640
&lt;br&gt;18:53:44.035088 IP 10.2.90.44.2270 &amp;gt; 10.1.2.15.5060: P 1:660(659) ack 1 win 16640
&lt;br&gt;18:53:44.035441 IP 10.1.2.15.5060 &amp;gt; 10.2.90.44.2270: P 1:561(560) ack 660 win 64876
&lt;br&gt;18:53:46.977653 IP 10.1.2.15.5060 &amp;gt; 10.2.90.44.2270: P 1:561(560) ack 660 win 64876
&lt;br&gt;18:53:46.981193 IP 10.2.90.44.2270 &amp;gt; 10.1.2.15.5060: . ack 561 win 16080
&lt;br&gt;18:53:47.119140 IP 10.1.2.11.445 &amp;gt; 10.2.203.101.2231: R 3473789694:3473789694(0) ack 3036828448 win 0
&lt;br&gt;&lt;br&gt;We again see the 3-way handshake, then two small packets, and where
&lt;br&gt;ther &amp;quot;serious&amp;quot; data transfer should start, we run into a timeout.
&lt;br&gt;&lt;br&gt;Path MTU discovery seems to be fairly OK, I can ping with long packets:
&lt;br&gt;&lt;br&gt;18:55:48.857712 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp 1296: echo request seq 1024
&lt;br&gt;18:55:48.857720 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp
&lt;br&gt;18:55:48.857982 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp 1480: echo reply seq 1024
&lt;br&gt;18:55:48.857993 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp
&lt;br&gt;18:55:49.865428 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp 1296: echo request seq 1280
&lt;br&gt;18:55:49.865434 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp
&lt;br&gt;18:55:49.865685 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp 1480: echo reply seq 1280
&lt;br&gt;18:55:49.865698 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp
&lt;br&gt;18:55:50.866921 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp 1296: echo request seq 1536
&lt;br&gt;18:55:50.866928 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp
&lt;br&gt;18:55:50.867183 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp 1480: echo reply seq 1536
&lt;br&gt;18:55:50.867193 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp
&lt;br&gt;18:55:51.868360 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp 1296: echo request seq 1792
&lt;br&gt;18:55:51.868367 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp
&lt;br&gt;18:55:51.868608 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp 1480: echo reply seq 1792
&lt;br&gt;18:55:51.868620 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp
&lt;br&gt;&lt;br&gt;Users claim that the issue with the Office Communicator started when
&lt;br&gt;the Netscren 5 GT which terminates the VPN tunnel (and has an &amp;quot;allow
&lt;br&gt;all&amp;quot; policy in place) was updated to ScreenOS 5.3.0r6.0 from some 5.0
&lt;br&gt;or 5.1 version a few weeks ago.
&lt;br&gt;&lt;br&gt;Now my questions
&lt;br&gt;&lt;br&gt;(1) Are there any known MTU issues in ScreenOS 5.3.0r6.0 for the 5GT?
&lt;br&gt;(2) How can I for testing purposes reduce the MTU the NSR client uses
&lt;br&gt;&amp;nbsp; &amp;nbsp; for data sent into the VPN tunnel? Setting the appropriate registry
&lt;br&gt;&amp;nbsp; &amp;nbsp; key on the virtual ethernet adapter does not work; the setting is
&lt;br&gt;&amp;nbsp; &amp;nbsp; simply igored (verified by ping with a big request packet)
&lt;br&gt;(3) Why do such MTU issues only surface with one application?
&lt;br&gt;&amp;nbsp; &amp;nbsp; Everything else seems to be just fine.
&lt;br&gt;(4) Which debugging steps would you guys take?
&lt;br&gt;&lt;br&gt;Any hints wil be appreciated.
&lt;br&gt;&lt;br&gt;Greetings
&lt;br&gt;Marc
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;-----------------------------------------------------------------------------
&lt;br&gt;Marc Haber &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;I don't trust Computers. They | Mailadresse im Header
&lt;br&gt;Mannheim, Germany &amp;nbsp;| &amp;nbsp;lose things.&amp;quot; &amp;nbsp; &amp;nbsp;Winona Ryder | Fon: *49 621 72739834
&lt;br&gt;Nordisch by Nature | &amp;nbsp;How to make an American Quilt | Fax: *49 621 72739835
&lt;br&gt;_______________________________________________
&lt;br&gt;nn mailing list
&lt;br&gt;nn@qorbit.net
&lt;br&gt;&lt;a href=&quot;http://qorbit.net/mailman/listinfo/nn&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://qorbit.net/mailman/listinfo/nn&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;&lt;/blockquote&gt;
&lt;/quote&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-reduce-MTU-for-a-VPN-tunnel--tp9641863p9700146.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-9700133</id>
	<title>Re: How to reduce MTU for a VPN tunnel?</title>
	<published>2007-03-27T14:11:41Z</published>
	<updated>2007-03-27T14:11:41Z</updated>
	<author>
		<name>Joekim13</name>
	</author>
	<content type="html">Which hardware are you using? if its an asic based such as ISG2k or NS5200 and your using Vsys or vlans try 5.4r3.
&lt;br&gt;&lt;br&gt;Also you can try adjusting MSS values.
&lt;br&gt;&lt;br&gt;set flow tcp mss 1400(default) try lowering to 1200.
&lt;br&gt;and 
&lt;br&gt;set flow max-frag-pkt-size (60 bytes less than mss)
&lt;br&gt;&lt;br&gt;&lt;br&gt;Joe
&lt;br&gt;&lt;blockquote class=&quot;quote light-black dark-border-color&quot;&gt;&lt;div class=&quot;quote light-border-color&quot;&gt;
&lt;div class=&quot;quote-author&quot; style=&quot;font-weight: bold;&quot;&gt;Marc Haber-6 wrote:&lt;/div&gt;
&lt;div class=&quot;quote-message shrinkable-quote&quot;&gt;Hi,
&lt;br&gt;&lt;br&gt;I am having issues with Windows clients using Microsoft Office
&lt;br&gt;Communicator through an NSR VPN. Client is Windows XP SP2 with NSR
&lt;br&gt;Client 10.3.5 (Build 6). I suspect this is an MTU issue.
&lt;br&gt;&lt;br&gt;When the Client is accessing the Live Communication Server directly,
&lt;br&gt;everything is fine:
&lt;br&gt;&lt;br&gt;18:51:39.770881 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: S 1182056209:1182056209(0) win 65535 &amp;lt;mss 1380,nop,nop,sackOK&amp;gt;
&lt;br&gt;18:51:39.770990 IP 10.1.2.15.5060 &amp;gt; 10.2.203.101.2247: S 689666419:689666419(0) ack 1182056210 win 16384 &amp;lt;mss 1460,nop,nop,sackOK&amp;gt;
&lt;br&gt;18:51:39.771223 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: . ack 1 win 65535
&lt;br&gt;18:51:39.774990 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: P 1:662(661) ack 1 win 65535
&lt;br&gt;18:51:39.775340 IP 10.1.2.15.5060 &amp;gt; 10.2.203.101.2247: P 1:562(561) ack 662 win 64874
&lt;br&gt;18:51:39.834843 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: . 662:2042(1380) ack 562 win 64974
&lt;br&gt;18:51:39.834956 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: . 2042:3422(1380) ack 562 win 64974
&lt;br&gt;18:51:39.835055 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: . 3422:4802(1380) ack 562 win 64974
&lt;br&gt;18:51:39.835123 IP 10.1.2.15.5060 &amp;gt; 10.2.203.101.2247: . ack 3422 win 65535
&lt;br&gt;18:51:39.835243 IP 10.1.2.15.5060 &amp;gt; 10.2.203.101.2247: . ack 4802 win 65535
&lt;br&gt;18:51:39.835501 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: . 4802:6182(1380) ack 562 win 64974
&lt;br&gt;18:51:39.835547 IP 10.2.203.101.2247 &amp;gt; 10.1.2.15.5060: P 6182:6877(695) ack 562 win 64974
&lt;br&gt;&lt;br&gt;We see the 3-way handshake, then two small packets, and then packets
&lt;br&gt;in the size range of the network MTU.
&lt;br&gt;&lt;br&gt;When the Client is going through the VPN, things go wrong badly:
&lt;br&gt;&lt;br&gt;18:53:44.028012 IP 10.2.90.44.2270 &amp;gt; 10.1.2.15.5060: S 3728511120:3728511120(0) win 16384 &amp;lt;mss 1280,nop,nop,sackOK&amp;gt;
&lt;br&gt;18:53:44.028108 IP 10.1.2.15.5060 &amp;gt; 10.2.90.44.2270: S 2496991569:2496991569(0) ack 3728511121 win 16384 &amp;lt;mss 1460,nop,nop,sackOK&amp;gt;
&lt;br&gt;18:53:44.029649 IP 10.2.90.44.2270 &amp;gt; 10.1.2.15.5060: . ack 1 win 16640
&lt;br&gt;18:53:44.035088 IP 10.2.90.44.2270 &amp;gt; 10.1.2.15.5060: P 1:660(659) ack 1 win 16640
&lt;br&gt;18:53:44.035441 IP 10.1.2.15.5060 &amp;gt; 10.2.90.44.2270: P 1:561(560) ack 660 win 64876
&lt;br&gt;18:53:46.977653 IP 10.1.2.15.5060 &amp;gt; 10.2.90.44.2270: P 1:561(560) ack 660 win 64876
&lt;br&gt;18:53:46.981193 IP 10.2.90.44.2270 &amp;gt; 10.1.2.15.5060: . ack 561 win 16080
&lt;br&gt;18:53:47.119140 IP 10.1.2.11.445 &amp;gt; 10.2.203.101.2231: R 3473789694:3473789694(0) ack 3036828448 win 0
&lt;br&gt;&lt;br&gt;We again see the 3-way handshake, then two small packets, and where
&lt;br&gt;ther &amp;quot;serious&amp;quot; data transfer should start, we run into a timeout.
&lt;br&gt;&lt;br&gt;Path MTU discovery seems to be fairly OK, I can ping with long packets:
&lt;br&gt;&lt;br&gt;18:55:48.857712 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp 1296: echo request seq 1024
&lt;br&gt;18:55:48.857720 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp
&lt;br&gt;18:55:48.857982 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp 1480: echo reply seq 1024
&lt;br&gt;18:55:48.857993 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp
&lt;br&gt;18:55:49.865428 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp 1296: echo request seq 1280
&lt;br&gt;18:55:49.865434 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp
&lt;br&gt;18:55:49.865685 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp 1480: echo reply seq 1280
&lt;br&gt;18:55:49.865698 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp
&lt;br&gt;18:55:50.866921 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp 1296: echo request seq 1536
&lt;br&gt;18:55:50.866928 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp
&lt;br&gt;18:55:50.867183 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp 1480: echo reply seq 1536
&lt;br&gt;18:55:50.867193 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp
&lt;br&gt;18:55:51.868360 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp 1296: echo request seq 1792
&lt;br&gt;18:55:51.868367 IP 10.2.90.44 &amp;gt; 10.1.2.15: icmp
&lt;br&gt;18:55:51.868608 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp 1480: echo reply seq 1792
&lt;br&gt;18:55:51.868620 IP 10.1.2.15 &amp;gt; 10.2.90.44: icmp
&lt;br&gt;&lt;br&gt;Users claim that the issue with the Office Communicator started when
&lt;br&gt;the Netscren 5 GT which terminates the VPN tunnel (and has an &amp;quot;allow
&lt;br&gt;all&amp;quot; policy in place) was updated to ScreenOS 5.3.0r6.0 from some 5.0
&lt;br&gt;or 5.1 version a few weeks ago.
&lt;br&gt;&lt;br&gt;Now my questions
&lt;br&gt;&lt;br&gt;(1) Are there any known MTU issues in ScreenOS 5.3.0r6.0 for the 5GT?
&lt;br&gt;(2) How can I for testing purposes reduce the MTU the NSR client uses
&lt;br&gt;&amp;nbsp; &amp;nbsp; for data sent into the VPN tunnel? Setting the appropriate registry
&lt;br&gt;&amp;nbsp; &amp;nbsp; key on the virtual ethernet adapter does not work; the setting is
&lt;br&gt;&amp;nbsp; &amp;nbsp; simply igored (verified by ping with a big request packet)
&lt;br&gt;(3) Why do such MTU issues only surface with one application?
&lt;br&gt;&amp;nbsp; &amp;nbsp; Everything else seems to be just fine.
&lt;br&gt;(4) Which debugging steps would you guys take?
&lt;br&gt;&lt;br&gt;Any hints wil be appreciated.
&lt;br&gt;&lt;br&gt;Greetings
&lt;br&gt;Marc
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;-----------------------------------------------------------------------------
&lt;br&gt;Marc Haber &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;I don't trust Computers. They | Mailadresse im Header
&lt;br&gt;Mannheim, Germany &amp;