Jun 23

StoneGate 5.2 – New log filtering improvements

Feature Previews, SMC -
1 Star2 Stars3 Stars4 Stars5 Stars (3 votes, average: 4.33 out of 5)
Loading ... Loading ...
No Comments »

Log browsing and filtering is one of the most frequent administrators’ tasks. That’s why we continuosly try to improve the workflows related to logs. In SMC 5.2 there are a few nice shortcuts that you can utilize when filtering the logs:

Log filtering shortcuts

Continue reading »

written by Tero Jantunen - 892 views \\ tags: , , , , , , , ,

May 20

StoneGate 5.2 – Integrated whois queries

Feature Previews, SMC -
1 Star2 Stars3 Stars4 Stars5 Stars (7 votes, average: 5.00 out of 5)
Loading ... Loading ...
No Comments »

Integrated whois queries

We have noticed that a lot of StoneGate administrators are constantly inquiring the country, city, organization information from these web portals:

  • http://www.ripe.net/
  • http://www.arin.net/whois/
  • http://www.afrinic.net/cgi-bin/whois
  • http://wq.apnic.net/apnic-bin/whois.pl
  • http://www.lacnic.net/cgi-bin/lacnic/whois

In order to save administrator’s time, StoneGate 5.2 has now integrated whois action. You can right-click any IP address in logs, statistics or reports. The results of whois query are displayed in a separate info dialog.

written by Tero Jantunen - 820 views \\ tags: , , , , , , ,

Dec 17

Clustering with insufficient IP addresses on a link

Various -
1 Star2 Stars3 Stars4 Stars5 Stars (2 votes, average: 3.50 out of 5)
Loading ... Loading ...
4 Comments »

It is not uncommon to wait for an ISP to lease sufficient number of addresses on the link until you are able to install a cluster which by default requires at least 3 addresses: 1- CVI, 2 – for each NDI for every node of the cluster (considering a simple cluster of two elements – to imagine a scenario with more nodes just add the corresponding number of NDI addresses).

Thus, for the cluster to work normally at least /29 mask on the link is needed.

Whereas most of the time ISPs provide only /30 mask by default. Luckily StoneSofft cluster technology allows clustering in that situation too.

To build a cluster one has to:

1) create a cluster element;

2) add a CVI for the external interface and uncheck the NDI checkbox;

After that the firewall will be up and successfully running even with VPN configuration.

BUT there are some subtle issues:

1) management should be, of course, at one of the internal interfaces,

2) static ARP entries should be made on external interfaces (which do not have an NDI) for the neighboring router IP address;

3) pings/traceroutes and other throubleshooting utilities will be unavailable through the external interface as those imply using the interface addresses which we are lacking in this situation.

written by DR - 1,720 views \\ tags: ,