Zone IP restrictions again

I just want to confirm there isn't an easier way to do this. I am attempting to lock down a Vibe 3.3 zone so it is only available from two internal subnets plus 1 specific IP. This zone doesn't have an external DNS entry and there is no proxy or other front end to the Vibe server. I create a role condition, added it to the defined roles, and re-indexed.
My conditions:
allow 10.228.14.*
allow 10.228.15.*
allow 10.228.29.43
deny *.*.*.*
And I get blocked from the .14 and .15 subnets as well. The *.*.*.* seems to block everything and not allow exceptions.
If I do this, though, it seems to do what I want:
allow 10.228.14.*
allow 10.228.15.*
allow 10.228.29.43
deny 10.228.29.*
BUT, following that pattern, I would have to have 253 deny statements, for 10.228.1.* to 10.228.255.* and then it looks like just the 3 exceptions would work.
Is there an easier way with a global deny? If I do break down and enter in all those denies, am I going to hit a limit or cause a performance impact? Ideas?
Thanks,
Todd B.

T.,
It appears that in the past few days you have not received a response to your
posting. That concerns us, and has triggered this automated reply.
Has your problem been resolved? If not, you might try one of the following options:
- Visit http://support.novell.com and search the knowledgebase and/or check all
the other self support options and support programs available.
- You could also try posting your message again. Make sure it is posted in the
correct newsgroup. (http://forums.novell.com)
Be sure to read the forum FAQ about what to expect in the way of responses:
http://forums.novell.com/faq.php
If this is a reply to a duplicate posting, please ignore and accept our apologies
and rest assured we will issue a stern reprimand to our posting bot.
Good luck!
Your Novell Product Support Forums Team
http://forums.novell.com/

Similar Messages

  • Access Restrictions again...

    Ok so I cant get the access restrictions to work. I input the mac addy of the pc i want to restrict and no matter what times I put in the pc can still acess the net. In other words, I can restrict it to 24/7 no access and it still wont work.
    Anyone able to get this to work? Im using WRT54GL v4.30.5

    I think i figured it out. You have to have the firewall enabled for it to work (duh) so far it seems to be working now.

  • HT201659 Help! can't play movies after turning on Restrictions on iOS 8.1.1

    Hi guys please help me solve this issue..
    I have synced a couple of movies from iTunes, then turning on restriction on Movies in my iphone 6+ (iOS 8.1.1).
    After checking that my movies really "dissapear" from Videos app, i turned off the restriction again to access the movie. There has been no problem after I turned on the restriction again and wait for a couple days.
    A couple days later, I want to access the movies again, so I turned off the restriction. But when i open the movie it doesn't play at all, and just return to the video summary screen, as if the movie had ended. And on top right corner there is a thin circle line like it was trying to download something, but it never really progressing to any stage.
    I have tried restarting the device, turning the restriction on and off, to no avail. Finally I erased all movies and synced it right back using iTunes and the problem dissapear, but I did the same thing and a couple days later it happened again.
    Please tell me that there are other ways to solve this other than re-sync to iTunes or via iCloud. Cheers!

    Hi Selena thanks for your reply. I just did that, not solving it. But now there's a new development.. I got a message saying Connect to a Wi-Fi network to play "movie_name"
    Then I also got another message saying:
    The Operation couldn't be completed
    mpavcontroller error domain error 3
    Which brings me to this thread discusssion:
    Mpavcontroller error domain
    Did what others do with their rented videos (my case is not rented videos though):
    1.  From Settings, signed out of iTunes.
    2.  Turned off iPad.
    3.  Turned on iPad.
    4.  From Settings, signed into iTunes.
    5.  Re-opened "Videos" and was able to view rental without error recurring.
    Did not work.. Help!!

  • Problem with an IPv6 iface in a zone if the corresponding physical is down

    Hi,
    I have a non-global zone with an IPv6 interface setup using zonecfg:
    add net
    set address=<address>/10
    set physical=<iface>
    end
    The corresponding physical interface is configured in the global zone and is a part of a VLAN, so, <iface> is something like ce123000 rather than ce0.
    It works perfectly, but... I do not really need this interface in the global zone. Following these recommendations - http://forum.java.sun.com/thread.jspa?threadID=5075412&messageID=9274814 and http://www.sun.com/emrkt/campaign_docs/expertexchange/knowledge/solaris_grid_perf.html#26 - I am setting the interface 'down' using ifconfig in the global zone. The problem is that the interface in the non-global zone stops working at this point. (According to ifconfig, it is UP, but it does not seem to transmit any packets.) If I set the interface 'up' in the global zone, the interface in the non-global zone starts working again.
    Am I doing/understanding something wrong? What can I do more to debug this? May this behavior be IPv6 or VLAN specific?
    Thank you,
    Vasiliy
    Message was edited by:
    vbaranov

    Looks toe like MAX and MIN are always going to be zero.

  • How to update the apps while disable Settings General Restrictions Installing Apps  ??

    Hi
    I will give my old iPad to my mom and I would like to disable  "Settings>General>Restrictions>Installing Apps"  so that she or other famliy kids will not unintentionally install some bad/garbage apps.
    But I found a problem, without Apps Store, the apps already there will not be updated any more !!  Am I right?
    It seems that we need Apps Store for apps update, but disabling the "Settings>General>Restrictions>Installing Apps" will remove the Apps Store.
    Does anybody know any way to work around? I mean the apps already there could be update while "Settings>General>Restrictions>Installing Apps" is disabled.
    Thanks a lot !!

    stanleyoowa wrote:
    You mean I need to unhidden the App Store everytime when I want to update the apps ?
    And then re-hidden the App Store to enforce the restriction again?
    It is reasonable, but sounds like ... not that handy ......
    I just wonder could I use "icloud" to enforce the apps update??
    Purchases, yes, but I don't think it works for updates.

  • IPad restrictions are on, need to be off

    I let a friend use my iPad, I locked settings down by setting a restrictions passcode, and now I cannot unlock, or turn off restrictions. It will not take any passcode, just takes my code to get into the ipad. I factory restored the iPad, and can modify anything, but when I restore from a prior backup, it locks restrictions again. I have initial pass code, just not the restrictions passcode. I need to restore to a prior backup, as I have, but need to remove restrictions so I can re-enable my e-mail accounts, and content that comes back from restore. Just need to know how to turn off these restrictions, and still have my information.

    If you are at a friends and they have their own wireless network then just ask them to allow the Apple TV and your phone onto it then you will be fine.
    The other option is an Airport Express. I'm considering getting one for hotel use, to set up a wireless network so I can use an Apple TV.

  • Zones or Containers Live Upgrade Solaris10 Update 8

    Good Day,
    I am running my Solaris OS in a ZFS root pool. My containers/zones are running in their own ZPOOLS. They are not part of the root pool.
    How can I get Live Upgrade to not make snapshopts of my running containers/zones?
    To shut the containers down and detach them is not an option.
    Many Thanks,
    Gilbert

    Our client has a strange request :-)
    The idea is to run live upgrade and patch the new boot environment. On the day of the reboot, the containers are detached before reboot. Once the Global Domain rebooted successfully, the containers/zones are atached again.
    They have limites space and don't have the luxury for Live Upgrade to make clones of their container/zone environments.
    I tried commenting out the running zones in /etc/zones/index but somehow, Live Upgrade still detects the running zone and makes a snapshot of the ZFS filesystem in that ZPOOL.
    Any suggestions?

  • Zone private area

    I use Sol-10 b54. As for now non-global zone can share some directories with
    global zone with read-only permission.
    I would like to know:
    1. Will it be proposed read-write technology of such share ?
    2. What about directories share not only with global zone but with non-global
    also ?
    3. Now I can create non-global zone with the similar set of packages as in
    global one. I don't like it. Is there any work around ideas? I'd like
    to see possibility of non-global zone creation with predefined package set.
    4. Is ZFS is the answer of all aforementioned questions?

    The "inherit-pkg-dir" resource can be used to specify a read-only file system
    that is shared or exported by the global zone into another zone.
    1. Will it be proposed read-write technology of such share You can do that today by defining a "fs" resource of type "lofs". But be aware
    that be doing so you're setting up a channel where the local zone can potentially
    affect the global zone (for example, by exhausting the space on the file system).
    2. What about directories share not only with global zone but with non-global
    also ?Yes, the global admin can set up such a file system, again by creating "fs"
    resources of type "lofs" into one or more zones. But again, it does mean that
    one zone can potentially affect another zone if such a file system exists in
    both read-write.
    With respect to #3, we're looking at methods of specifying a subset of
    packages to copy into a zone when it's installed. For now, you can specify
    some of the affected directories, like /opt, as "inherit-pkg-dir" resources or
    in some caes, you can use pkgrm(1M) if they packages came from an
    unbundled product.
    As for ZFS and zones, stay tuned as there should be some very nice
    synergy between these two technologies.

  • Time Zone keeps defaulting to GMT

    I have a problem. My MacBook Pro running 10.5.8 won' retain the proper time. I am in time zone PST and whenever i reset the time to the correct PST time AND zone it does not work.
    What is the fix, it looks like a software bug to me.

    Hi Steven,
    In the Finder head to the "Go" menu, choose "Go to Folder..." and type in /etc
    Now look for the "localtime" folder (within the etc folder) and drag it to trash. (It will ask you to authenticate yourself as someone with admin permissions when you do this).
    Now go to System Preferences (under the Apple menu) and set your date, time zone etc up again.
    The problem usually occurs because of an issue arising from an earlier migration.
    ( This achieves the same result as the terminal approach mentioned in the other link, and is somewhat quicker and easier to perform)
    Cheers
    Rod

  • Lofiadm not work in ZONE

    I used lofiadm to mount an ISO image file in a zone, it compained that -
    the file "/dev/lofictl" did not exist,
    then I exported this device from the global zone and tried again, this time, the preivious error message was gone,
    but this command seemed never to return back after I issued it:
    lofiadm -a /tmp/sol-10-u1-companion-ga.iso
    Please help.
    PS:
    My box info is :
    SunOS csw 5.11 brandz_release i86pc i386 i86pc

    http://docs.sun.com/app/docs/doc/817-1592/6mhahuotb?a=view

  • Whimsical Time Zone Problem

    I've been noticing during the month I've had my iPhone that, while it keeps good time, often it'll show the time for the wrong time zone. For instance, today it showed the time as 2:40 pm. I panicked for a second thinking that I had forgotten to pick up my son from school. Then I realized it couldn't possibly be 2:40 pm. I've had this problem before, so it was easy to assume it was wrong this time, too. But I've seen it more than an hour off also. The minutes are always correct.
    Anyway, once I plug my iPhone into my computer, the time zone syncs up again and it shows the correct time.
    I always have my iPhone set on my correct city as far as Time Zone goes. But is there another setting I don't have set right, or is this a genuine bug, or what?

    You are using it correctly.
    There are several issues with the iPhone which relate to the time zone and setting the time.
    We are all hoping that Apple fixes these in the next software release (and hoping that is soon).

  • I have forgotten my ipod restrictions password?

    i have forgotten my ipod restrictions password?

    If you forgot your restictions password, you'll have to set it up again as new device, without using the latest backup. This password is part of the backup and will lock the restrictions again if you restore from your backup.
    You will lose all other settings and data that can't be transferred to your computer and which are part of the backup.
    iTunes: About iOS backups
    How to back up your data and set up as a new device

  • How can I change a restrictions passcode without losing all the restricted settings?

    We have two iPads for two boys... both are heavily restricted.  One of my boys saw the passcode and I changed it by disabling and then re-enabling restrictions, only to be shocked when ALL MY SETTINGS were reverted to default and DIDNT come back after enabling restrictions again.  How can I change the passcode on the other iPad without losing all the settings, especially the long list of blocked websites?
    Thanks in advance.

    What good would the passcode be if you could bypass it like that?

  • How to remove iDVD Template Drop Zones?

    Hi! I'm looking to remove all drop zones from iDVD to have a simple black background that could be replaced with a .mov file.
    Essentially, I'd like to remove the 3 drop zones from the "Modern" 7.0 theme.
    Please let me know if this is possible, thanks!
    Alex

    This is from iDVD Help: _Adding or hiding drop zones_
    The drop zones in a theme are a permanent part of the graphics or animations included in that theme. Therefore, you can’t add drop zones, delete individual drop zones, or change the location of drop zones on a menu. You can, however, hide all the drop zones on a menu so that they don’t appear in your final project. This is particularly helpful when you want to create a simple custom theme.
    To hide all drop zones on a menu screen:
    Make sure the menu whose drop zones you want to hide is showing in the iDVD window.
    With your pointer over the menu, press Command-I to open the Menu Info window.
    Deselect the “Show drop zones and related graphics” checkbox.
    The drop zones immediately disappear from the menu, and they do not appear in your final burned project. Some other graphical elements may also be hidden.
    You can always show the drop zones and ornaments again after you’ve hidden them. Simply open the Menu Info window and select the “Show drop zones and related graphics” checkbox.
    To replace the background, open the menu info window. For full directions, go to iDVD Help, and look up _Changing the background image of a DVD menu_.
    I hope this helps.

  • Disable/Enable Restrictions

    Hi
    Anyone spotted this funny behaviour;
    You open up Restrictions to disable say, Installing Apps, then you go back, and try open up Restrictions again, Installing Apps is enabled again! You have to do it twice (at least) so the third time you check, it is properly disabled.

    Well, there's not. Restrictions are not designed to be used the way you want to use them. Again, tell Apple:
    http://www.apple.com/feedback/iphone.html

Maybe you are looking for

  • New To Solaris 10

    Hi This is Pawan for the first time i have downloaded Solaris 10 download only to windows (5 CDs) and i have unzipped and i tried to write the image on to the CD by using NERO 6 by clicking the option make boot able disc but finally I failed in creat

  • Hp laserjet 3055 won't scan in windows 8

    I have a HP Laserjet 3055 All In One printer/scanner/copier/fax/cusinart and it will print on my new Lenovo desktop with Windows 8 but will not scan.  It is hooked up at the computer and the HP device by USB.  Little help for a Luddite out there?

  • SharePoint and FrameMaker 10 CMS/Integration - Checked Out Files Stuck

    Hello, I originally set up the CMS connection to my SharePoint through FrameMaker using the domain name as a part of the user name (as suggested in a previous post), but have still run into this same issue discussed in that post, (unalterably locked

  • Unavailable 'page protection' smartforms

    Hi all. I need all parts of a table in a smartforms, be shown in the same page. If I select the table, and select 'Output Options', there is a flag 'Page protection', but it is in display mode, and I can't put it in change mode to mark it. Could you

  • Logic:  When recording audio, a loud electronic buzz happens

    I am using Logic 9 on an iMac. I use Logic to transfer records and create MP3s. The record player is connected to my stereo receiver, the receiver to the input of an MAudio FW 410, the MAudio FW 410 to my external hard drive, and my hard drive to my