Not signed in (Sign In)
Welcome, Guest

This forum is now Read Only. Visit our new forum at: forum.gta.com.

Bottom of Page
Firewall Configuration and Implementation: Protocol 41 tunnel? ipv6 in ipv4? Being blocked...
  1.  
1 to 2 of 2
Jun 18th 2009
Hi,

For the first time on our network two WS2008 machines are attempting to communicate from the DMZ segment to the Private segment, via a GB800e.

The call takes 30 seconds to complete - a quick check of the GB800's logs shows "proto=41" being blocked, and wireshark shows the servers trying to use ipv6 over ipv4.

A quick google shows up that the servers are trying to use something along the lines of: http://en.wikipedia.org/wiki/Tunnel_broker but the GB800 seems to be blocking this.

I'm not using NAT in the GB800 - the Wikipedia article states that "proto-41 tunnels (direct IPv6 in IPv4) may not operate well with NATs".

Is this some misconfiguration at my end? I can't see where to un-block the proto-41 tunnel - I can't see a block rule that includes this.

Is this normal behaviour for a GTA firewall? It's unlikely, but perhaps they don't support this kind of traffic?

Have any of you come across this before, or can offer any insight as to what I'm missing?

Thanks for reading!

Kenny
Jun 18th 2009
There should be more to the block. Is it a pass through block or outbound, or remote access?

Sometimes there a rule number? This will also show where it blocked.

In your Pass Through definition you may wish to make sure inbound is checked and you have a remote access policy allow the service on both directions.
  1.  
1 to 2 of 2
Top of PageBack to discussions