[pca] PCA and ipfilter

John Horne john.horne at plymouth.ac.uk
Mon Aug 4 17:15:29 CEST 2008


On Fri, 2008-08-01 at 13:53 +0200, Martin Paul wrote:
> Hi,
> 
> > However, trying to check for the recent update (pca --update=check) did
> > not work - it was blocked. It seems the network traffic was coming from
> > 131.130.186.80. Allowing this through ipfilter, and the check then
> > worked fine.
> 
> Indeed - about three months ago the IP address of www.par.univie.ac.at 
> has changed from .100 to .80 in the 131.130.186. network.
> 
> > Can I ask if there is a specific set of IP addresses, or a range, that I
> > should allow through in order to ensure that PCA works.
> 
> I can't speak for sunsolve.sun.com, but the address for 
> www.par.univie.ac.at shouldn't change again soon. You could add 
> 131.130.186.0/25 instead, which should be even longer lasting.
> 
> Best thing would be to use a stateful firewall setting, of course, as 
> all connections will originate from pca inside your network.
> 
As a slight follow-on to this, be advised that the Solaris 10 ipfilter
(4.1.9) has a problem with the 'keep state' setting, in that it drops
connections which it should let through! Needless to say this is not too
good! Sun are aware of it, and if you have ipfilter log dropped/rejected
connections you will see them with the 'OOW' indication (out-of-window).
At the present I have left ipfilter configured, but it is not
'stateful'.


John.

-- 
---------------------------------------------------------------
John Horne, University of Plymouth, UK  Tel: +44 (0)1752 587287
E-mail: John.Horne at plymouth.ac.uk       Fax: +44 (0)1752 587001



More information about the pca mailing list