Hello
 
I need help, please !!!
I have two boxes Nokia IP330 with VRRP run FW-1 v.41 sp5 + hotfix - ipso 3.4.1.
See MYnetwork topology:
 
                                              -----------------
                                              |  internet   |
                                              ----------------     (tcp/ip)
                                                      |
                             --------------------------------------------------------
                             |  (master)                                         | (backup)
                       ---------------                                       ---------------
                        router X --------------- HSRP-------------     router Y
                       ---------------                                        ---------------
                              +++++++++                +++++++++
                                            ---!-----------------!-----
                                                   HUB 
                                            ------------------------
                                                       !
                                            ------------------------
                                                SWITCH L2
                                             ---!---------------!-----
                               +++++++++               +++++++++
                       ---------!--------                                  --------!---------
                        IP330         -------VRRP ------ -----       IP330
                       ---------|-------                                    -------|----------
                                ++++++++                  ++++++++                
                                            ---!-------------------!--
                                                SWITCH L2
                                             ---!------------------!--
                                                        +
                                                        +  (tcp/ip)
                                             ------------|---------------
                                                MQ SERIES         (NAT) 10.X.X.X -----> 200.X.X.X
                                                     (IBM)
                                              -------------------------
To begin with I have very drop's connections in  rule 0 :   Internet Users  ----->   MQSeries   or     MQSeries --------> Internet Users   message: unknown established tcp packet  I have no idea. My friend said: The tcp/ip - sync  --- ack   ---syn-ack . When the two devices are out of sync (the Application MQ and Client Extern)the session is lose. Is it true?  Why firewall drop connection?
 
Thanks. Best regards.
Tutu
 
 

Reply via email to