Sunday, April 23, 2006

Firewall upgrade

I had upgraded my Nortel Contivity router with its latest firmware and all of a sudden traffic seemed to reach only my ISP's gateway but not beyond.Initially I thought it was the ISP's issue but then they confirmed that there was no issue on their side.I had a look at my routing table and the default gateway was set to the next hop of one of our serial links .But in my configuration for the router I had not configured it like that anywhere .The ISP gateway was in the same subnet as my public ip so that was the reason why their gateway was reachable but not the other destinations.I searched through the static route entries and the default gateway specifications and saw a new check box to verify public default route .I checked it and then refreshed the routing table.That did not help.
Next I thought of checking out the interface config of the serial links and there stood a new check box for default route .It was not there in the older version of the GUI for the firewall. It caused that interface to be the default route and hence the other entry where I had specified the public default route was not being effective.Well I unchecked it and things started working fine.

No comments: