How to setup Firewall - Need Help

I have 2 connections to the internet via BGP. I need to place firewalls for border security. I need to use the FWSM modules on the 6506 that are also acting as my dual core.
These firewalls will also do NAT. My problem is with load-balancing. I want to be able to load balance & provide redundancy over the firewalls but dont know what my options are.
If I inject 0.0.0.0 default routes into my OSPF on the BGP routers, my core will have 2 default routes and traffic will pass over both firewalls. I believe that if return traffic takes a different path the return firewall will not have session or xlate information and will drop the traffic. Ok so I can use "tcp bypass" to fix the session problem, but what about the xlate when using PAT?
What is the best design strategy when implementing 2 firewalls and load-balancing them in this fashion.
Attached is my network setup. I can subnet IPs if needed to, etc.
Please help.

Firewall load balancing is supported when both are configured in Active/Active Failover mode where both are actively handling incoming traffic. The Active/Active Failover is only available when the firewall's are configured in multiple context mode and the they are not VPN endpoints. The multiple context mode means dividing a firewall into multiple virtual firewalls (contexts). Each context works independently as an individual firewall and has its own configuration. Then the user can load balance these contexts (virtual firewalls) to be active on either of the physical firewalls. In other cases the only option is to use a router in front of the firewall for load balancing.

Similar Messages

  • Setup Problem - Need Help Please!!

    My problem is a low hum eminating from my speakers every time I connect my MPC2000 sampler to my audio interface.
    My setup consists of the MPC2000, a Dj Mixer, and my laptop which has an M-Audio interface which I use to connect the mixer & MPC. Basically, as soon as I remove the cables that connect my MPC or my mixer to my interface, the hum stops. I've tried different cables, new cables, a ground adapter for the MPC to change it to 2 prong, and nothing helps. The only thing that DOESN'T cause this hum when plugged into my interface, is my keyboard, so i'm quite sure the interface itself isn't the problem.
    Does anyone know what might be causing this interference that's resulting in a hum? I have exhausted all my own theories and am desperate for some sort of help! Many thanks in advance!!!

    Hi beirut,
    Try the following:
    1.Put the mpc2000,the dj mixer and your computer all in the same power outlet from the wall.
    2.Go to home despot and buy a few gray-colored ground lift plugs (they must be gray)
    3.With these gray ground lift plugs,lift the MPC2000.test the system.No hum=solved problem.hum still there or different,list the DJ mixer.
    4.Is your DJ mixer hooked up to turntables? If so,you need to ground the turntables to a proper ground.Good turntables have a little wire coming out of them,just for that purpose.
    5.Try turning off any TVs,refridgerators,fluorescent lighting(the ones that look like office lights),and other things around your place,and see if the hum goes away.
    6.Try using a DI box for your DJ mixer,to plug it in to the DI,and then out to the audio interface.
    7.And Most Importantly... RUN AND BUY A DIFFERENT BRAND OF AUDIO INTERFACE!!!!!!!!!! M-Audio...yucky yucky yucky!!!
    Cheers

  • Windows Setup Error, Need Help

    so i just tried to install what i think was XP home edition on my MacBook. I picked the partitioned boot camp disk to install it to, and all went well until the setup was complete. After setup was finished copying files, my computer rebooted and came to a black screen that read something like "press any key to boot from disk. . . . ." then it displayed a message something like "disk error, press any key to restart." so i pressed a number of keys but nothing happened. i couldn't eject the disk or get anything to happen so i had to do a cold shut down. I rebooted and when it came to the black screen again i pressed a key before the error popped up and it took my directly back to the windows setup.
    so basically im stuck going through the setup. although now i cant get past the part that asks you which disk to copy windows to, because its already been setup on the boot camp disk. i cant eject the windows CD or figure out how to get back to the mac OS.
    Im pretty bad at computers so any help would be great, its either this or i take it to an apple store. Does anyone know what might be causing this problem?
    Thanks.

    Two things you might try. After turning the power off, hold down the switch below the scroll pad when you reboot. This should eject the install disk. Alternatively, when you start to do a cold boot after powering down, hold down the option key. You should eventually see icons for the possible operating systems. With the arrow keys move the cursor to the MacOS operating system, and then hit the return key. This should boot you in Leopard.

  • How to implement this need help

    I created a datacontrol for a named query which (using Ejb entity beans) which accepted a employee id and click on find show me the respected employee details in a table.
    case 1: In one single page
    when i added the form consisting of a single text box , button and the table to show the result of the find method in one single page it worked out perfectly,,,
    case 2 : using 2 different pages
    But then i tried adding only the form in one page named page1 and and the table to show the result in another page i.e page2 , Also in the command action of find button of page1 i asked it to redirect to page 2 and show result . But it never showed me any results..
    Question :
    1) How to implement case2 i.e to have a form on one page and the resultant table to be show on another page i.e When users sees first page he adds the employee id in text box and clicks find .The user then needs to be redirected to page2 and the result of search should be shown in table...
    Can anyone guide me over this... ???

    Hi,
    you use a method on the EJB that takes a argument (e.g. the employee ID). You then put the method result set on page 2 (the method argument shall be pointed to a request or session attribute using EL : #{sessionScope.EmployeeId}
    On the search page - when the user hits the search button - you set the attribute "EmployeeId" in the session before navigating to the next page
    Frank

  • Documaker 12.1 - ODBC - SQL Setup Error - Need  Help

    Hi
    We are facing issues while trying to checkout/read the resources from the SQL tables. We are getting an error "An error occured getting the file". We use "ODBC" driver for connecting to SQL database and the ODBC test connection seems to run succesfully. This doesn't seems to be a connectivity issue as we are able to see that the resources are listed in IDE.
    Studio somehow is not able to read/load the data from the application data table. Do we need to set-up any access privileges for the database and tables to enable the DMStudio to access it.
    Thanks in Advance.

    Hi,
    When you run the Create New Workspace wizard in Documaker Studio and select your DBMS type it tries to deploy the tables through our ODBC connection.
    If successful it will then create the workspace with some minumum resources and query for other info like Font Cross-reference file, etc. and when done you have a complete workspace which includes INI, DFD configuration files specific to your choice of DBMS type. This workspace and it configuration files (e.g. fsiuser.ini, fsisys.ini, deflib\carfile.dfd, etc.) are needed for access to the workspace properly.
    If the wizard is unsuccessful (for reasons such as permissions, access, etc.) it will let you generate a DDL and pass it off to the qualified personnel but it expects you to either leave the studio running and continue from there or to re-run the create workspace to complete the task and configuration. If you stop at the DDL stage and don't complete the task but try and use internal defaults for the configuration files the resource may appear to deploy but they will not load upon studio preview or attempt by the publishing engine to process with them because the internal configuration does not use the appropriated datatype for the database. This situation would be classified as improper or incomplete workspace creation.
    I suspect you hit this problem. Going back and configuring a workspace to just talk to the database is not appropriate and can have undefined results.
    Hope this helps,
    -Steve

  • O2 email setup! need help

    hi i need some help. im trying to activate my blackberry with o2. ive added blackberry umlimited to my monthly plan so thats up and running but to activate it i am meant to go to o2email.co.uk but when i go to this site and put i my imei number and pin it keps saying - the phone is already registered with another service provider and that should be re-registered.
    this phone is 100 % brand new it came from my friend in a box sealed and he works for BT who supplied it.
    i dont understand whats going on and even several people at o2 dont.
    i dont know what to do to get this working so please help.
    thanks.

    Welcme to the Frums!
    I am not familiar with your question, but there are many on here that are! They will be able to help you! I just wanted to welcome you here 
    Nurse-Berry
    Follow NurseBerry08 on Twitter

  • HT3819 I want to share my music that I purchased on iTunes and in my library with my daughter to put on her ipod touch, but it since the 11.01.1 update to iTunes, I'm not sure how to do it; need help!

    I want to share my purchased music on itunes with my daughter's ipod touch, however it seems with the new itunes update, either you can't or don't know how; please help

    Nothing has changed in this regard.
    What is it exactly that you canot do now, that you could do before?

  • I don't know how to download movies need help

    How do I download movies on my iPad pls?

    Purchased movies FAQ
    http://support.apple.com/kb/HT1906

  • Need help getting ALL iTunes from old comp hard drive

    Old computer XP Home died after house was hit by lightning. Surge protector gave it's life but not enough to save the day. However both hard drives from old computer are fine and function via connection of USB external hard drive enclosure.
    New computer is Vista Home Premium on AMD64duo w/4G RAM and 500GB hard drive.
    Connected old hard drives to USB and can see everything. Did Import Folder and copied most files from old iTunes Music directory. (I say most files because iTunes continues to crash after approx 10 minutes of this copy process. On 17th try now.)
    Can see and play the music that got copied but artwork is gone. Playlists are gone. Ratings gone. Basically all the preferences of how I had the old iTunes setup.
    Needing help in understanding how to get Artwork and anything else I can from the old iTunes.
    Have not tried to plug in iPod yet. Will wait atm.
    First old drive had Program files and Second old drive had all Data files.
    AMD64 AthlonX2   Other OS   Vista Home Pre AMD64 duo 4G
    AMD64 AthlonX2   Other OS   Vista Home Pre AMD64 duo 4G

    First, I followed the instructions on this site for Backing up itunes library by copying to a external hard drive.........
    That's what it does. It makes a backup copy of the iTunes folder. iTunes will not use that folder or do anything to that folder.
    All that succeeding in doing was mirroring whatever I did on the C:/ drive on the E:/ drive i.e. if I deleted itunes from the C:/ drive it disappeared from the E:/ drive.
    Do you mean after you followed the instructions and copied \Music\iTunes folder to the external drive and then deleted something from iTunes, it deleted it from the external drive also?
    As above, iTunes will not use or do anything to that folder.
    Next, I followed these instructions for Moving the itunes media folder to the external drive.
    Why? You already copied the entire iTunes folder (including th emedia folder) to the external drive.
    Hold Shift and launch iTunes.
    Select *Choose library* and select the _iTunes library.itl_ file in the iTunes folder on the external.
    This too didn't help as the media folder is not the problem, its the library as its 735kb!
    What do you mean "the library"?
    735kB is small for the iTunes library.itl file and a single file in iTunes is larger than that.
    Am I right in thinking there's no way of moving the library to the external drive whilst wiping it from the C;/ drive?
    Yes. Follow my intruction above (Choose library) and iTunes will use the iTunes folder on the external.
    You can then delete \Music\iTunes on the C: drive.

  • Need help connecting to wifi and bluetooth

    Can't connect to wifi or bluetooth.  Keep getting told incorrect password.  I'm keying in the correct password.  Any suggestions on how to fix?  Need help!!

    You'll have to give us some more info as far as error messages or screen shots (Shift-Command-3).

  • How to setup osx Firewall to allow incoming access to nginx?

    Hello!
    How to setup osx Firewall to allow incoming access to nginx (any port)?
    Local access is all fine, but when I trying to open http://<myip>:<port> from outside (other device in same network) there are no answer.
    If I turn off Firewall all works fine, but I want to keep my safety.
    Adding "nginx" binary file to Firewall  list doesn't help.

              "Victor" <[email protected]> wrote:
              >
              >Hi,
              >
              >I need to limit access on one JSP to a user. All the
              >other JSP's
              >should be available to averyone all the time. The following
              Victor,
              two ideas:
              1. Once you've seen where jspservlet compiles the jsp to, try adding
              an explicit servlet registration (then an acl for that servlet)
              I'm not sure if it would work, never tried.
              2. If it doesn't, well, you have a servlet class available from
              the jspservlet/jspc process. Move it to servletclasses (or wherever
              you keep other servlets) and register/acl it normally
              

  • How to setup user's rights to modify Windows Firewall Rules?

    I would like to have an account in my system that doesn't have any other administrative privileges besides rights to modify the Windows Firewall rules by means of Firewall API. How to setup a minimal set of rights for this account to do the task?
    Right now what I see is that if I try to call INetFwRule::put_RemoteAddresses from an account without administrative privileges, the call fails with access denied. There is no means to find out access to what is needed. The call fails even if the process
    is run under high integrity level.
    I tried to setup global security audit, but there were no relevant events logged.
    I tried to monitor the process with procmon, there were no any access denied events logged.
    I tried to give the full access for this account to the correspondent registry keys. It didn't help.
    I stepped firewallapi.dll in a debugger and found out that what fails is an RPC call to some COM interface proxy. I assumed that probably it is a remote call to some HNetCfg.FwRule method. I tried to add the user account to the HNetCfg.FwRule launch and
    access permission ACLs in the DCOM configuration utility. It didn't help either.
    Dear Microsoft, why did you do such a simple thing as settings user rights so difficult? Can you reveal the secret what rights and privileges I have to set?
    Thanks in advance.
    Dei nostra Matrix est.

    Here is what I found so far.
    The firewall service calls RpcServerRegisterAuthInfo to setup RPC security from FwRpcAPIsRegisterAuthInfo. It happens during registration of RPC interfaces in FwRpcAPIsInterfaceCreate. FwRpcAPIsInterfaceCreate is called from FwRpcAPIsInitialize. And FwRpcAPIsInitialize
    is used from FwServiceAsyncStartupRoutine.
    After calling FwRpcAPIsRegisterAuthInfo function FwRpcAPIsInterfaceCreate calls ConvertStringSecurityDescriptorToSecurityDescriptor, which converts a textual description of a security descriptor to some binary form.
    So my guess is that access rights are hard coded inside mpssvc.dll and what I have to do is just to find the textual representation of the correspondent descriptor.
    I found 8 descriptors inside mpssvc.dll:
    O:SYG:SYD:(A;;RCWD;;;BA)(A;;RCWD;;;NO)
    O:SYG:SYD:(A;;RCWD;;;S-1-5-80-2940520708-3855866260-481812779-327648279-1710889582)(A;;RCWD;;;S-1-5-80-3526382388-830156861-4107432654-3665941875-1028450966)
    O:SYG:SYD:(A;;RCWD;;;S-1-5-80-62724632-2456781206-3863850748-1496050881-1042387526)
    O:SYG:SYD:(A;;RCWD;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)
    O:SYG:SYD:(A;;RC;;;BA)(A;;RC;;;NO)(A;;RCWD;;;CY)
    O:SYG:SYD:(A;;RCWD;;;BA)(A;;RCWD;;;NO)(A;;RC;;;CY)
    O:SYG:SYD:(A;;RCWD;;;BA)(A;;RCWD;;;NO)(A;;RC;;;AU)
    O:SYG:SYD:(A;;RC;;;AU)
    I don't know yet which one corresponds to changing a firewall rule.
    Dei nostra Matrix est.

  • Urgent :need help to setup Master to snapshot(read only) environement

    Hi,
    I need your help urgently. I don't know much about master to Snapshot configuration. I need to do prototype of master to snapshot(read only) as soon as possible. I need replication setup/configuration scripts.
    DB1 is master database (8i) and DB1 is Snapshot site db.
    both dbs are identical except they have different Global_name.
    I want to replicate table from DB1---> DB2 unidirectional.
    Global name for DB1 is DB1.world and for DB2 is DB2.world
    TNS names are DB1 and DB2 respectively and TNSNAMES.ORA file is same on both server.
    Schema owner of Mster site (who owns the tables that I want to replicate) is user 'SYNAPSE'. On DB2 I have also same schema with same tables. Lets say table called 'TEST' that I want to replicate from DB1 to DB2.
    for simplicity I want to have only one account(user) on both site who can do administration and take care of all other task including replication.
    I need scripts to do setup for the replication environment described above.
    In short please provide me script to replicate DB1 to DB2 (Master to snapshot).
    I appreciate your help very much.
    You can reach me at [email protected] as well.
    Thank you.
    Pravin

    Finally I figured out how to setup/configure master to Snapshot environment but I have to say that Oracle documents are very confusing.
    The problems I ran into are:
    User Repadamin can't create MV in schema owner other than repadmin. Work arround I used is let that schemema owner allow to create MV.
    Other proble ran in is Constraint(FK) violation when trying to do using refresh group. To resolve this problem either disable constraints on snapshot site or create constraints usinf deferred option.
    Pravin

  • Wish I didn't upgrade! and now I need help to figure out how to make it wor

    I have a Windows XP Pro 2nd edition with IE ver 6.0.2 (but I normally use FireFox)
    I've never had any trouble with iTunes until iTunes "forced" me to upgrade my iTunes applicaiton to version 6 if I wanted to "purchase" music. (note to self: Purchase music from stores it's much safer)...
    I upgraded and received no error messages. Trouble is now, when I launch the iTunes application it doesn't "open" ... although the iTunes process begins to run in the background process (ctraltdelete).
    I have uninstalled and installed 5 different times and ways.
    First uninstall was "typical" uninstall. THat didn't fix it.
    Second uninstall was "typical" unistall from the Control Panel, and then I removed the folders from the "program File" folder. Still wouldn't work.
    Third unintall was "typical" then I removed folders from local drive and removed all "known" registry "itune" keys. That didn't work.
    Fourth uninstall was first a "repair" to itunes, and then a "typical" uninstall, then I removed folders, removed registry (does anyone know all of itunes registry keys? Maybe I am missing a few.. the only ones I know of is the "itune" reg). Then I looked through my start up menu from "msconfig" and took a look at my firewall program to see if there was anything preventing the program from running...
    Fifth uninstall pretty much fruitless as my previous attempts.
    I know it HAS to be a registry key of some sort.. here's why:
    When I uninstall and reinstall (no matter how thourough) every time I install the iTunes program Windows XP has never ONCE recognized the new install of iTunes as a "NEW PROGRAM" and it should!
    I need help... what registry keys should I be removing? ANyone suggest for me to remove Quick Time too? What about the ipod updater software? Any connection?
    HELP??????????????????
    THanks
    W.

    hi wmchisholm!
    Trouble is now, when I launch the iTunes application it doesn't "open" ... although the iTunes process begins to run in the background process (ctraltdelete).
    hmmm. is itunes.exe persisting in Task Manager? if so, first check up on these two possibilities:
    iTunes 6 won't open on a Windows computer if firewall software is not up-to-date
    iTunes for Windows doesn't open after upgrading
    but if itunes.exe is disappearing after a few seconds, try the following technique:
    Using MSCONFIG to troubleshoot conflicts in Windows
    ... and let us know the names (exact spelling please) of the start-up items that you had to disable in order to get itunes to launch. (there's a nasty piece of malware out there that has been causing "error-less" itunes launch failures since late October.)
    love, b

  • Need help rush for a spa3102 special setup welcom gurru

    I have to transport phone line on my network . I just bought two spa3102 that is supposed to do the job. I know how to setup the adresses but don't know anything on how to setup both to communicate together . I just need to take an analog line in spa3102 number one and over the local lan , let the other spa3102 answer like a standard phone . And make call from the second one to the fist one using it's analog line . Could someone help me i'm really in a pain with this ...
    Please your help will be appreciate
    thanks !

    Hello MF DOMO,
    try to read this article :
    http://www.provu.co.uk/pdf/sipura/spa_backtoback_2x_spa3000.pdf
    or other articles under the Linksys heading on the page :
    http://www.provu.co.uk/support.html

Maybe you are looking for