View Single Post
  #4 (permalink)  
Old 2006-06-16
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: anti-spoof problem

You really don't want to do that. When you push a policy, even if the SmartCenter is behind the firewall, the connection is to the EXTERNAL interface, through the firewall if need be. If you disable the external interface, you're probably hosed.

"fw unloadlocal" is not totally benign because it leaves the enforcement module unable to protect itself. On a Nokia, that's not necessarily bad. On a Windows enforcement module, it's not so good. :-)

Stopped logging? Can you SSH to it and make sure it's not out of disk space? When it can't contact the SmartCenter, it will begin to log locally.

I presume your SmartCenter is behind this firewall?

Ray
Reply With Quote