RVS4000 V1 tracks some VLAN to VLAN connections backwards

Firmware         V1.3.3.5
Operation Mode:        Gateway
VLANs:             4, one per LAN subnet
Inter-VLAN Routing:     Enabled
I've got all of the management interfaces of the infrastructure devices
(switches, UPS,WAPs) on the default VLAN 1 that is configured on as untagged on
all relevant ports. I've noticed that the router will track most of the routed
connections from the non-default VLANs to devices on the devices on the default
VLAN backwards, where the destination is listed as the source and vice versa,
often with the SYN_SENT state instead of ESTABLISHED as reported by the source
host.
I get this information from the IP Conntrack view launched from the
Status/Gateway screen. This is how a telnet connection from a computer on the
guest VLAN 3, subnet 10.0.89.0/24 to the default mgmt VLAN 1, subnet
192.168.75.0 looks in IP Conntrack
Basic Information                 Original Direction                             Reply Direction
Protocol     Life Time     State         Source IP     Source Port     Destination IP     Destination Port     Source IP     Source Port    Destination IP     Destination Port
TCP         44         SYN_SENT     192.168.75.98     23         10.0.89.2     50196             10.0.89.2     50196         192.168.75.98     23
Also, there are corresponding entries in the router's access log. 
Jan 29 22:26:00 - [Access Log]I TCP Packet - 192.168.75.98:23 --> 10.0.89.2:50196
Notice that it  is incoming as expected as opposed to outgoing (to the WAN port).
I know that these are routed connections, for when I turn off Inter-VLAN
Routing, I cannot make any connections from on VLAN subnet to another.
This reversed connection tracking anomaly is causing the firewall ACLs that I have
implemented to block traffic from the guest VLAN (3) to the default
(infrastructure) VLAN to not work, since ACLs are defined based on source IP
and destination IP. Connections to other VLANs other than the default appear as expected
in the access log and the IP Conntrack view.
Is this a known bug with the RVS4000 V1?

Thanks for answer.
I investigated thread you sent and found there the solution, which can be shorten to one line:
Setup -> Advanced Routing -> Inter-VLAN Routing -> Disable
Once more, Many THX
It works and is solved.

Similar Messages

  • ISA550 Deny access to management login on some vlans/ports

    Hi,
    I tried to create a firewall ACL rule that would deny access to http/https on the router for some vlans/ports, but it seems like the rule is just ignored.
    Also; I can ping all interfaces on the router even between to vlans that are using a same level zone. Even connect to the management login from a different access vlan port.
    The main issue is that I don't really like to expose a webserver on a securitydevice to everyone on the LAN side. And I would also like to isolate all vlans and create exceptions if I need to.
    Anyone know if this is possible?

    Hi Prithvi Manduva,
    Thank you for replying!
    I have tried to set up two simple rules to illustrate my problem. My configuration is this:
    VLAN 1: DEFAULT  in zone OFFICE
    VLAN 2: CONFIG in zine CONFIG
    With Vlan 1 and 2 assigned to port 2 and port 3 in access mode-
    DHCP is enabled on both vlans with subnets of 192.168.5.0/24 for OFFICE and 192.168.10.0/24 for CONFIG
    CONFIG_IP is 192.168.10.1
    DEFAULT_IP is 192.168.5.1
    Using these two rules:
    #     FromZone     ToZone     Service     SourceIP     DestinationIP     Action
    1     CONFIG     Any     HTTP     Any     CONFIG_IP     Permit  
    2     Any     Any     HTTP     Any     DEFAULT_IP     Deny  
    I would think that this would allow the CONFIG zone to access port 80 on config IP, and also deny all other zones to access port 80 on the default gateway for Office (DEFAULT_IP)
    I also tried to create a simple Deny ICMP Echo Request to the DEFAULT_IP, but it looks like it's just ignored.
    In short, it looks like I can't deny anything to any of the IP addresses of the interfaces on the router.

  • RV320 loosing WAN and inter VLAN connectivity

    I just received a new RV320 V01 router and I am having trouble with the router loosing WAN and inter VLAN connectivity. Anywhere from 2 to 24+ hours the router will stop routing traffic to/from the WAN and other VLANs on the network. I have a ping trace running on one system and all packets are lost when the routing fails to all WAN connections and systems on other VLANs. I am still able to ping all of the router address for the VLANs i.e. 192.168.1.1, 192.168.2.1, 192.168.3.1 etc. Unfortunately I only have one system on this VLAN so I do not know if I can ping other systems on the same VLAN. I also do not have any DNS resolution when the issue occurs.
    The router is set up using a single ISP connection on WAN1 using DHCP assignment. WAN2 is disabled in the router settings. The router has version v1.1.1.06 firmware. I have also tried disabling VPN pass-through as noted from other posts. When the issue occurs the WAN1 connection is showing as “Connected (Inactive)” with no assigned IP address, gateway or DNS servers. The router is in gateway mode and everything works fine until the problem.
    Any Ideas?

    You noted that the WAN 1 connection has no IP address when this occurs.
    When it occurred last, I noted the "Connected (Inactive)" on WAN1 and that there were no IP addresses assigned.  I have a screen shot of the page attached.  I had noticed the "Connected (Inactive)" previously when the problem was occurring but cannot definitely say there were no IP addresses at that time.  I do not recall if I noticed this before or after I had disconnected the WAN1 to test a direct PC to modem connection.  I did check with the cable company and there are no issues being noted or logged on my connection.  The direct PC to modem connection worked fine.
    What type of Internet connection is it? (Cable, DSL, T1, etc)
    The connection is Cable
    Is the WAN port configured for DHCP?
    The WAN port is configured for DHCP
    Who is the ISP?
    The ISP is the local cable company
    When the issue occurs, can devices within a subnet ping each other?
    As I noted in the original post, at the time I was on a VLAN that only had one system running to monitor ping traces.  I will try again next time the problem occurs to have multiple devices on the same network.
    Are there any switches in the network?
    Yes, there is a switch in the system.  I am using a cisco SG200-26.  However, the problem persists even when I directly connected a PC to the active LAN port on the router.  No issue when the PC was dirrectly connected to the modem.
    Can you draw a simple topology showing the network with IP addresses, VLANs, etc?
           See attached

  • Hi, I have the iPhone 4, 32GB, version 4.3.5 (8L1) and for some reason when I connect it to the laptop, it starts synchronising but never goes beyond step 1. I have tried evrything, but it does not work and now I cannot update the iPhone s/w. any clue?

    Hi, I have the iPhone 4, 32GB, version 4.3.5 (8L1) and for some reason when I connect it to the laptop, it starts synchronising but never goes beyond step 1. It goes on syncing forever, without actually doing anything. I have tried everything, wiped the phone numerous times, deleted all files from the laptop but still no resolution. As a result, the phone does not really synchronise.
    This started somewhere in May 2011 when I upgraded what proved to be a problematic s/w version and the phone has not recovered since.
    Now I cannot update the iPhone s/w any longer.
    Any clue?

    You may have to try deleting all the music from your phone (by going to Settings>General>Usage>Music, swipping All Music and tapping Delete), then sync it all back on with iTunes in order to fix this.

  • TS1424 Tried to use my apple id to update some apps and got"Connection Manager::invoke:: Failed to find service connection url"  After this occured a few times I reset the id password, and this was confirmed by email.  It still fails with same message.  I

    Tried to use my apple id to update some apps and got"Connection Manager::invoke:: Failed to find service connection url"  After this occured a few times I reset the id password, and this was confirmed by email.  It still fails with same message.  Ideas?

    Hi, you have to logout from your iTunes account and reconnect it:
    Settings / iTunes & App Stores / ...
    https://mobilfunkexperten.de/news/13450/sporadische-probleme-im-itunes-und-app-s tore
    Hope this helps... :-)

  • Weird: Soloing a track some other tracks aren't muted

    I get a strange behaviour of Logic (9.1.3)
    If I "solo" an audio track some other audio tracks aren't muted as they should...
    On the contrary all instruments strips are regularly muted....
    Very strange...
    What can be happened??

    mnstudio wrote:
    I had the concerning aux strips solo-safed...
    That sounds strange. And incomprehensibly limiting. Why did you do it ?
    Christian

  • I can not connect to iswifter, some times it is connected and some time it shows " UNABLE TO CONNECT TO SERVER PLEASE CHECK THE INTERNET" but my internet connection is good and other wbe site i can open without any problem. Please guide  me..

    I can not connect to iswifter, some times it is connected and some time it is not connected and getting message " UNABLE TO CONNECT TO SERVER , CHECK YOUR INTERNET" but my internet connection is ok and I can open other web site with out any problem.  Please guide me how to solve this issue.

    Can't connect to the iTunes Store
    http://support.apple.com/kb/TS1368
     Cheers, Tom

  • Anyone can point me out on some proper steps to connect my new iPhone5c to my old MacBook running an updated 10.6 OS?

    Hello,
    Anyone can point me out on some proper steps to connect my new iPhone5c to my old MacBook running an updated 10.6 OS? Cannot make the iPhone to connect to he MacBook (Bluetooth) even the latter has already paired the new device and it seems ready to use.
    The iPhone only want to forget the device (my MacBook) while it cannot connect to it.
    I also created a WiFi network on my MacBook and joined the iPhone to it - cannot see it anywhere.
    I have connected the iPhone to the Macbook using the provided USB cable but Finder does not show the iPhone, that only presented me with the option to trust or not the Computer the moment I plugged in the USB cable.
    Am I missing something? Am I doing something wrong?
    Thx,
    Iul

    Unless you're trying to Tether, your phone won't pair with your Mac...file transfer, by Bluetooth, is not supported.
    Your phone won't appear in Finder, as Disk mode is not supported on any iPhone.

  • HT4628 some times my internet connection will say it has timed out and I can not connect. but my friends mac never has a problem. How can I fix this?

    some times my internet connection will say it has timed out and I can not connect. but my friends mac never has a problem. How can I fix this?

    Just confirming, when you have the trouble, the wifi icon is grayed-out or has all bars showing? I believe you are saying that is is grayed-out - not connected to your wireless router.
    I have a Mini that started to lose connection to the Internet after the 10.7.3 update but still showed the wireless as connected. If I pinged the wireless router, I would get a quarter of the packets failing to return. The router was a Netgear that supported 802.11N connections. As a test, I set it to 802.11G (54MBps) maximum and the Mini worked fine for a week - no dropouts. And for the other devices that did support 802.11N, while there was a noticeable delay with downloads and pages loading, they still worked.
    As another test, I changed the Netgear router to a Billion 802.11N model and the Mini has not had a problems since. (It is still using 802.11g). So it could be your router that is causing trouble for your Mac.
    Have a look at some of the More Like This postings in the right column. There has been a number of Mac owners experiencing wifi connection issues and some very good suggestions as to how to resolve their issue.

  • I have multiple AppleTV's at different locations.  Is it possible to determine which specific AppleTV purchased a movie, by tracking some type of physical device ID (similar to a hard coded MAC address or serial number)?

    I have multiple AppleTV's at different locations.  Is it possible to determine which specific AppleTV purchased a movie, by tracking some type of physical device ID (similar to a hard coded MAC address or serial number)?

    Mullaly75 wrote:
    I assume u guys don't understand what open source software is
    Yes, I think most of us do understand what open source software is. It sounds as if you don't. Here's some information:
    Open-source software (OSS) is computer software that is available in source code form: the source code and certain other rights normally reserved forcopyright holders are provided under an open-source license that permits users to study, change, improve and at times also to distribute the software.
    Open source software is very often developed in a public, collaborative manner. Open-source software is the most prominent example of open-sourcedevelopment and often compared to (technically defined) user-generated content or (legally defined) open content movements.
    from http://en.wikipedia.org/wiki/Open_source_software
    Yes, Tom Wu of Stanford wrote a paper on something called Secure Remote Access Protocol. It's a form of Asymetric Key Exchange and has nothing to do with hacking anything. It's actually intended to protect data.

  • Hi All,  I am trying to install informatica 9.1 HF 2 connecting to 11g DB.  when installing Informatica, I am at the DOMAIN CREATION windows and inputting the DB connect details and for some reason, it cannot connect to the DB.  The DB is running   any id

    Hi All,
    I am trying to install informatica 9.1 HF 2 connecting to 11g DB.
    when installing Informatica, I am at the DOMAIN CREATION windows and inputting the DB connect details and for some reason, it cannot connect to the DB.
    The DB is running
    any ideas?
    the error message states:
    THE CONNECTION FAILED: CORRECT THE DATABASE INFO AND TEST THE CONNECTION AGAIN..any help please
    thanks

    Yup, that did it.
    I actually had been made aware of the patch when I downloaded CF, but for some reason I thought it was difficult to install (I thought that you could only use the installer package if you could open Administrator). IAC I downloaded the appropriate patch file, ran it and Administrator ran. There was something in the install notes about reconfiguring the websites and removing the IIS6 Management feature but I'm not going to fool with anything because right now at least CF is running.
    Thanks.

  • We haven't been able to validate your Adobe Muse subscription for some time. Please connect to the I

    We haven't been able to validate your Adobe Muse subscription for some time. Please connect to the Internet in order to continue using Adobe Muse -- what does this mean?

    Eunonna please see Sign in or activation errors | CS6, CS5.5 Subscriptions, CS6 Perpetual - http://helpx.adobe.com/x-productkb/policy-pricing/activation-network-issues.html to resolve your current difficulties activating your software.

  • HT204406 new mix-song added (120 mb, mp3, different tracks, some in aac converted) - itunes match waiting - error, close

    new mix-song added to itunes (120 mb, mp3, i tried different tracks, some in aac converted) - itunes match waiting - error, close
    after a few minutes it gives an error and closes the window.
    small tracks are no problem. and the max limit is not reached
    some ideas?
    greetings from germany

    I wanted to first thank you for this, as this is the only workaround literature that seems to be floating around out there.  With that said, I know it is a big ask, but is there any way that you could create a video showing step by step how to do what you do?  I have several tracks that are stuck in waiting mode, and if left in itunes, will never upload or match...they only cause the upload process to hang up and restart.  I've tried leaving it for days...I've tried converting the files, signing in and out of itunes (and itunes match), updating itunes match, and I tried your technique...unfortunately to no avail.  Perhaps I didn't do your technique correctly.  I used audacity to reverse the audio.
    ANY help would be GREATLY APPRECIATED!!!
    Thanks

  • I lost my iPhone 5 and i wanted to know if i am able to track it down if its connected to a matcbook or any other compare without wifi and sim card?

    i lost my iphone 5 and i wanted to know if i am able to track it down if its connected to a macbook or any type of computer without wifi and sim card? i have a lock on it but i still want to know if they try to reboot it will i be able to find out theyre doing it?

    If you went into Find My iPhone and sent a lost request, or you tried a remote wipe, if the device was off line, then you would receive something if it was to go online. Did you have a passcode on the device? Did you have iOS 7 installed on it? If so, then even if they try to restore the phone, they will not be able to activate it because of Activation lock. Only certain things will get you a notification, and if they cannot get into the phone, you will not receive that. Without your Apple ID and password, the phone is useless to them if they try to restore it.

  • SF300-24 VLAN connected to RV180

               I have a location that had an RV042 and an unmanaged switch. I need to add a second network for some clients of the business and also add that network to the existing AP1240 so I need a second VLAN.
    I swapped out the existing router and switch with the RV180 and SF300.  The RV180 is connected to a DSL modem and uses PPPoE. It also has a gateway to gateway VPN setup. I have Internet connectivity and the tunnel is up.
    I added another VLAN on the RV180 and set port 1 to be untagged for VLAN 1 and tagged for VLAN 9 and configured another network for VLAN 9 and a DHCP server.
    Port 1 of the RV180 is connected to port 1 of the SF300.  That port is set up as trunked and untagged for VLAN 1 and tagged for VLAN 9 . I initially set up port 24 as access and untagged for VLAN 9 and excluded for VLAN 1.  I connected my notebook to port 24 and it never gets an address from the DHCP server for that VLAN. As a test I flipped port 1 of teh RV180 to untagged for VLAN 1 and connected my notebook and it gets an IP address on the corerct subnet and has Internet connectivity.
    I reviewed the config on the switch a number of times and also power cycled the switch and the router. I gave my notebook a static address on the correct subnet for VLAN 9 amd connected it to port 24 and I can't ping the gateway.
    Connectivity is fine on anyrthing connected to the ports untagged on VLAN1
    I attached some screenshots.
    Appreciate any ideas.

    Thanks for the reply.
    The subnet on VLAN 9 is 192.168.9.0 and the gateway is 192.168.9.1
    I am sure I was trying to ping the 192.168.9.1 gateway.  I also tried pinging 4.2.2.2 and there was no reply. I can ping 4.2.2.2 from a computer on VLAN 1
    The first problem I noticed is that my notebook did not get IP info from the DHCP server on VLAN 9 when I connected my notebook to port 24 which is configured as access and untagged for that VLAN.
    As a test I gave my notebook an address for the VLAN 9 subnet and also gateway and DNS info. There should have been Internet connectivity at that point. I think the subnet and DHCP for that VLAN are working properly since I can connect my notebook to the router and set that port to be untagged on VLAN 9 and I have Internet connectivity.

Maybe you are looking for

  • HP Officejet 6500 E710n-z is USB to desktop running Windows 7. I am XP Pro can"t find printer

    I have downloaded the network diagnostic utility. When I run it it won't let me get past finding the printer. It wants it to be hooked up with ethernet cable which ain' going to happen. The printer is hooked to a desktop Dell running Windows 7 that i

  • Create a dynamic dropdown field in Adobe Acrobat Pro XI

    Hello all. I am trying to create a field in one of my forms using Adobe Acrobat Pro XI. I have a dropdown list of "main" items, and based on what is selected in that list, I want a second dropdown list to give different choices. I have searched and s

  • How to delete an ou and everything underneath it

    I am trying to delete an ou from our directory by: ./ldapdelete -D "cn=orcladmin" -w xxx -p 999 "full dn" but am receiving the following error: ldap_delete: Operation not allowed on nonleaf Is there a switch to indicate i want the ou deleted and ever

  • DVD Menu Creation

    When creating a menu with text in Photoshop, Indesign, whatever.. Once we bring the file into DVD Pro.. the text looks jaggid and horrible.. Can anyone tell me why? The menus were created at 720 x540 and it's a SIMPLE MENU.. Nothing crazy whatsoever.

  • AVK does not find common libraries

    In our current JBoss application we have commons-logging.jar in a lib directory common to all WebApps. Now we run AVK 1.4.2 prior to a migration. How to tell AVK about this common lib? Once it helped to copy it into C:\j2sdk1.4.2_08\jre\lib\ext, but