Preventing Windoze Servers IPv6 Stack From Coming Up Behind FWSM

Hello,
We recently noticed that a sysadmin brought up a Server 2008 box behind one of our firewalls and was able to RDP to the box though we have rules explicity blocking RDP.
Further investigation discovered that the connection was through protocol 41 (ipv6) and that the sysadmin's desktop was Windoze 7 and both it and the 2008 box had their ipv6 stack enabled against our best practices.
Our network is (sort of) ipv6 enabled but there still is no addressing plan nor do I have the near term cycles to translate all my firewall rules from v4 to v6.
It appears that the server got a valid v6 address through stateless autoconfig even though v6 is not enabled on the FWSM it appears to be allowing the Router Solicitations (RS) out and the Router Advertizements (RA) back in which allows the box to autoconfig.
How can I prevent misconfigured systems in the future from getting autoconfig addresses.  My understanding is even if the autoconfig fails and it fails back to a link local address it still may be able to use a Teredo tunnel.
We have blocked protocol 41 explicity on all the interfaces which will drop a lot of the tunneling (back home to Redmond) but we want to ensure that autoconfig fails so the box just gives up on preffing v6 or tunneled interfaces and fails down to v4.  We have observed with a half baked v6 connection the clients have to wait for v6 attempts to time out resulting in complaints that the network or server is slow.
Yes, I know - spank the sysadmin and get them to follow process is one solution as is enabling v6 of the FWSM then dropping all the traffic but I'm looking for a stopgap.
"ipv6 nd suppress" on the cat6500 "outside" vlan does not work as the IOS we are running does not support the "all" keyword so RAs are dropped but those in response to a RS aren't.

Hello,
We recently noticed that a sysadmin brought up a Server 2008 box behind one of our firewalls and was able to RDP to the box though we have rules explicity blocking RDP.
Further investigation discovered that the connection was through protocol 41 (ipv6) and that the sysadmin's desktop was Windoze 7 and both it and the 2008 box had their ipv6 stack enabled against our best practices.
Our network is (sort of) ipv6 enabled but there still is no addressing plan nor do I have the near term cycles to translate all my firewall rules from v4 to v6.
It appears that the server got a valid v6 address through stateless autoconfig even though v6 is not enabled on the FWSM it appears to be allowing the Router Solicitations (RS) out and the Router Advertizements (RA) back in which allows the box to autoconfig.
How can I prevent misconfigured systems in the future from getting autoconfig addresses.  My understanding is even if the autoconfig fails and it fails back to a link local address it still may be able to use a Teredo tunnel.
We have blocked protocol 41 explicity on all the interfaces which will drop a lot of the tunneling (back home to Redmond) but we want to ensure that autoconfig fails so the box just gives up on preffing v6 or tunneled interfaces and fails down to v4.  We have observed with a half baked v6 connection the clients have to wait for v6 attempts to time out resulting in complaints that the network or server is slow.
Yes, I know - spank the sysadmin and get them to follow process is one solution as is enabling v6 of the FWSM then dropping all the traffic but I'm looking for a stopgap.
"ipv6 nd suppress" on the cat6500 "outside" vlan does not work as the IOS we are running does not support the "all" keyword so RAs are dropped but those in response to a RS aren't.

Similar Messages

  • How can I prevent the S5's screen from coming on when charging completes?

    I got my S5 today and it seems to have a "feature" that will be very damaging to the OLED display.  When it's done charging, the screen comes on and stays on.  I've been going through all the settings I can find and don't see anything that will prevent this.  Since static images burn into OLED screens, this is the last thing I want.  It's done the same thing several times.  My old phone (Galaxy Nexus) didn't do this.  When the Nexus finished charging, it did so with no fanfare.  The screen stayed off.
    When the S5 is locked and the screen is off, there's no reason for the screen to come on for anything short of a phone call.  It certainly shouldn't come on and stay on just because the battery finished charging.  And, any time the display does come on without user input, it should turn off again automatically if it's idle for the length of the screen timeout.
    I've got "Smart stay" turned off and "Screen timeout" set to 1 minute but, after it self-activates, it stays on indefinitely.  I've let it go for 20 minutes and the screen is still on.  How can I fix this?  If I can't get this behavior to stop, it's going back to the store.  I'm not paying $600 plus tax to have my lock screen burned onto my phone because I charge it at night.

    Okay I've tried safe mode.  Let it run down to 98%, plugged it in, locked the screen, and waited.  A few minutes later, the screen came on showing the 100% icon at the top right, full battery icon just to the left of the time, 100% text to the left of that.
    I'm not going to do a hard reset until I have confirmation that this is not normal behavior for the phone because that's going to take hours of my time and gigabytes of data transfer to get all of my media and apps back on the phone and configured.
    After all my griping, I do have to give credit where it's due.  This phone is much more efficient than my Galaxy Nexus.  I left the S5 running in WiFi hotspot mode while on battery last night.  It still had over 50% left on the battery.  The Galaxy Nexus would be stone dead after about 4 hours.  I can live with that if I have to but I'd really rather be able to leave it on the charger at night.

  • Any solution for preventing converted data (to excel) from crashing?

    Any solution for preventing converted data (to excel) from crashing - file crashes on a consistent basis.

    Hi Shrinivas,
    LabVIEW is getting bug fixes and new features with each version step.
    But new features also can bring new bugs - and not all bugs from older versions are fixed by now…
    The MixedSignalGraph is a beast of it's own and known to have bugs inside. The one you noticed now is probably one of those.
    So it's not your fault your VI terminates rather "unhappy", but most probably NI's fault. You can have a workaround as described in the last post.
    If I have to take same data from wire as you mentioned, I need to save the data in some variable
    No, you don't need any "variable"! THINK DATAFLOW: the wire is the variable!
    I have to write the data to excel file using report generation tool kit or some other way. … Please let me know if I can do it in some other easy methods. 
    It all depends on the datatype of your data. There are functions to save to spreadsheet files. You can save in binary files. You can create TDMS files , which can be read by Excel too. All those functions are really easy to use - you just have to look at the example VIs coming with LabVIEW!
    Best regards,
    GerdW
    CLAD, using 2009SP1 + LV2011SP1 + LV2014SP1 on WinXP+Win7+cRIO
    Kudos are welcome

  • How do I stop my screen saver from coming on too quickly on my MacBook Pro 2012, How do I stop my screen saver from coming on too quickly on my MacBook Pro 2012

    How do I stop my screen saver from coming on too quickly on my MacBook Pro 2012

    MacBook Pro
    https://discussions.apple.com/community/notebooks/macbook_pro
    https://discussions.apple.com/community/mac_os?view=discussions 
    http://www.apple.com/support/macbookpro

  • How can I prevent my new Mac Air from freezing in Safari

    How can I prevent my new Mac Air from freezing in while using Safari?

    Hi nainmom,
    Thanks for visiting Apple Support Communities.
    I recommend starting with these steps if your iPod nano is not recognized by your Mac:
    iPod not recognized in iTunes and Mac desktop
    http://support.apple.com/kb/ts1410
    Best,
    Jeremy

  • How to prevent a text in script from displaying if its value is zero

    Dear all,
    How to prevent a text in script from displaying if its value is zero
    for eg   Price  = 0.00
    if price is 0 it should'nt appear in output.
    I tried with    if price ne 0.
                       price = &price&
                        endif.
    but it's not working.
    Regards
    Raj
    <MOVED BY MODERATOR TO THE CORRECT FORUM>
    Edited by: Alvaro Tejada Galindo on Jan 20, 2009 8:59 AM

    Hello Nagaraju,
                           What you were doing is partially right.
    The correct format to write in the script is as follows :
    /:  if &PRICE& ne 0.
      &PRICE&
    /:  endif.
    This should work. Let me know how it goes.
    Nayan

  • Does anyone know of a VI or how to go about writing one that will prevent the computers time/date from being disabled while an application is running.

    Does anyone know of a VI or how to go about writing one that will prevent the computers clock/time from being disabled while an application is running. The time and date can normally be reset while an application is running by clicking on the time/date in the lower right-hand corner of the computer screen. I have an application that runs over several days and it is critical that the time and date of the computer not be changed. Is there an easy way to lock this out from the user? Note that I am what I consider an advanced beginner in LV.
    Thank you,
    Chuck
    Solved!
    Go to Solution.

    That is not something you can do from LabVIEW, as it is an operating system operation, and it will depend on the operating system that you're using. On Windows you can use a group policy to control this. Please Google on "prevent time and date change in windows".
    Also, please try to refrain from stuffing your entire message in the subject block. Keep the subject short, but descriptive enough so it can be understood what you are basically asking. Thanks.

  • In windows live photo gallery it says an error is preventing the photo or video from being displayed

    in windows live photo gallery it keeps saying an error is preventing the photo or video from being displayed

    Hi Frank.
    Thanks for the response.
    Agreed, the pertinent question is why can't my colleague edit the JPG exported by Aperture. It's probably also worth pointing out, the same problem occurs with JPGs exported from iPhoto.
    The Windows software usually plays nicely with JPGs by all acounts, just not the ones I send - which I do via eMail or my public space on Mobile Me incidently.
    So, another key question is: all settings being equal (color profile, quality, etc.) are the JPGs as produced by iPhoto and Aperture indistinguishable from those produced by other apps on other platforms - i.e. does the use of JPG enforce a common standard?
    If that is the case, I suspect ours might be a permissions issue.
    According to the Microsoft support page on editing in Windows Live Photo Gallery, the inability to edit a picture is commonly caused by unsupported file type, or read-only attribute set on the file.
    Unfortunately, he and I are not in the same place, and he's not particularly au-fait with this type of problem solving. Hence, before involving him, I'd like to know:
    1. it's possible (i.e. someone else does it), and,
    2. what's involved (at my end and/or his).
    Thanks again,
    PB

  • I have been having trouble with re direct and I have set this option in the tools folder. Is there a way to block these sites from coming up on redirect?

    Even though I set up the option in firefox to block redirects. it still happens. is there a way to block those redirect sites from coming up?

    Even though I set up the option in firefox to block redirects. it still happens. is there a way to block those redirect sites from coming up?

  • How to receive an RFC message in PI ABAP stack from ECC

    Hi mates,
    I am involved in a scenario in which we want to receive a message in PI (ABAP stack) from ECC (ABAP stack as well).
    We created a RFC destination (3) in sender system (ECC) so both stacks could be linked. However, we do not know how to receive this message once we are in PI Abap stack.
    In sender system code, a call destination takes place, an this destination stands for the one destination i noted before.
    BUT, as this RFC does not exist in PI, i wonder what steps have to be done in PI in order to be able to get the message from ECC.
    Hope you guys can guide me through this. Any help
    Thanks a lot in advance and best regards,
    david

    Hi Anand,
    No no, i do not want to create any sender RFC Comm Channel.
    What i want is to receive (by means of no PI adapter) a message in PI (abap stack) from ECC (abap stack), just by a RFC connection (type 3) between both systems.
    I will try to explain in more detail what i want to achieve:
    1) A standard SAP program is executed in ECC, at the end, a call destination is done.
    2) This destination call, calls an RFC destination that points to PI (RFC dest in SM59, type 3)
    (Until now, nothing is done in PI, there is no sender adapter, we just linked both ABAP stacks)
    3) In ABAP stack of PI, we want to receive the message, make any transformations and send the target emssage to PI adapters
    4) From that moment on, a ordinary PI integration is done.
    So my question is, what kind of stepd so i have to perform to get the message from ECC in PI without creating any object in PI (ESR, ID, i mean). Just as if we wanted to receive a RFC message, lets say, in BI (abap side) from ECC.
    Hope you got me this time.
    Thanks a lot in advance.
    Best regards,
    david
    Edited by: David de Miguel on Dec 27, 2010 11:48 AM

  • How does one prevent a folder's contents from being read while running in target disk mode?

    I want to prevent a folder's contents from being seen or used by a second computer that is connected to my iMac when it is running in the firewire
    target disk mode. Whenever I put my iMac into the Target Disk Mode all of its disk contents, for all users on its disk, can be seen and used by the second computer without needing any passwords.  Does anyone know of a simple way, short of using FileVault, for protecting folder contents when viewed while running in the target disk mode? I would like to protect the entire contents of my "Documents" folder from being viewed by anyone that connects to my iMac via the firewire target disk mode.

    Many users make a password protected Disk Image using Disk Utility to keep selected files protected. I have one such image myself that I keep on my Desktop containing passwords and such. I'm not sure if you could put the entire contents of your Documents folder into a secure disk image but you could certainly make one and put your most sensitive items in it within your Documents folder.
    I agree with you for not wanting to use FileVault. I've never used it myself and am very leery of it due to things I've read from other users.
    Regards,
    Steve M.

  • How can I prevent my Camera Archive import from being interrupted by timecode breaks?

    I'm trying to create Camera Archives from my old mini-dv tapes. I have a Sony Handycam DCR-TRV22 connected via FireWire. When I start the Camera Archive import process, everything is fine for a while but then the process stops with a message about a break in the timecode preventing the archiving from completing.
    Solutions to this problem I've seen online relied on changing import preferences in Final Cut 7. Unfortunately, I only have Final Cut Pro X and I'm not sure how to control this setting.
    I don't really care about timecodes, I just want to dump the entire tape to disk so I have a backup of the tape but the timecode break is interrupting the process and making me get involved a lot more often during the import process.
    Does anyone know how to force Final Cut Pro X to push through timecode breaks in a Camera Archive import?

    To clarify, this problem is not simply making me get involved more, but is preventing the Camera Archive operation from completing.

  • How do you stop the welcome to firefox 4 screen from coming up every time I open firefox? I get two tabs, one the welcome window, then my home page. How do you stop the bloody welcome screen?

    How do you stop the welcome to firefox 4 screen from coming up every time I open firefox? I get two tabs, one the welcome window, then my home page. How do you stop the bloody welcome screen?

    Its not my home page, Like I said, I hae my home page also come up in a different tab (google) I also get the welcome to FF4 on a seperate tab. My home page is set to google. But I dont want the welcome screen to pop up

  • How can you prevent the mac book pro from unexpectedly shutting off and beeping three times repeatedly?

    How can you prevent the mac book pro from unexpectedly shutting off and beeping three times repeatedly?

    The three beeps are an indication of a hardware problem. Power On Self-Test Beep Definition - Part 2 - Apple Support

  • Removing J2EE stack from dual-stack installation

    Hello.
    Does anyone know if it's possible to remove the JAVA-stack from a ERP6.0 dual-stack installation ?
    We have a ERP 6.0 system running HCM services. The ERP system is installed as dual-stack, but the JAVA-stack is not in use as we also installed a separate NW 7.0 JAVA system hosting portal and java hcm services.
    Thank you.
    Gerhard.

    Hi,
    Yes, you can drop Java part from existing dual stack system.
    1) Stop cenrtal service instance and all dialog instances of your system.
    2) Also, stop J2ee engine of CI from SMICM.
    3) Hash out all Java parameters in your default and instance profile (like j2ee, exe/j2ee, exe/jlaunch, jstartup etc.)
    4) Delete central service instance.
    5) Delete Database schema
    6) Delete directories (/usr/sap/<SAPSID>/DVEBMGS<xx>/SDM and /usr/sap/<SAPSID>/DVEBMGS<xx>/j2ee)
    Thanks
    Sunny

Maybe you are looking for