Guantlet on Solaris 2.5

2007-12-25 9:27:00

Thanks for the quick responses. Everybody pointed to a DNS problem. Here

we are using a split DNS, with the Gauntlet firewall as the external, and

a dedecated server for internal DNS. The firewall resolv.conf was pointing

back to it loopback address instead of the internal DNS. Thus the firewall

was unable to reverse lookup internal addresses to verify against its

net-perm table. The reason it would work after about 3-5 mins is the

resolver would time out and Gauntlet would then just use the IP address for

verification. This was really a case of too many cooks in the kitchen, and

very bad communication between me and my fellow Sys Admin's. Thanks again for

the quick pointers.

Chatch Ingersoll

Comments

Got something to say?

You must be logged in to post a comment.