Re: Management server behind another NGX FW When pings are failing, have you dug into where it is going wrong? Does the router have the right routes? And cluster B, does it have a route via cluster A? What do your routing tables tell you? Are all devices seeing ARP entries for each other correctly? Is this a Nokia cluster? Have you configured the Nokias to receive a multicast MAC reply? Your router may also need a static entry. Same with the switches. What does tcpdump tell you? Where are the packets going? Standard stuff for troubleshooting really - if you can't ping something (assuming you allow it), then you need to trace the path through the network, find out what is happening to your packets. As for what traffic you need to allow through, take a look at the implied rules for an idea. |