CSM 3.3.1: Range of addresses IP or IP Pool in ACL

Hello

Anyway is to use a range of IP addresses in an ACL?

I know that there are object-group...

I would use the IP as the Pool of IP VPN range.

Is this possible?

see you soon

Unfortunately not.

The ACL can support ranges of ip addresses, you can use only the subnets with netmasks to group ip addresses.

I hope it's clear.

Tags: Cisco Security

Similar Questions

  • Retrieve an IP address from the IP pool allocated for ESXi VTEP

    I had a Pool of IP of 5 addresses that have been assigned to my ESXi 5 hosts. Then, I messed up the port VTEP vmkernel on one of the ESXi servers. Only, I was able to fix by adding another IP to the IP address Pool range and then force a sync. Now, I have a Pool of IP show 6 of 6 IP addresses allocated when actually I only have 5 of the 6 allocated to the ESXi hosts. Is it possible for me to get the IP address 6th in the pool that shows always allocated?

    Thank you

    Try the REST API call

    REMOVE https:///api/2.0/services/ipam/pools//ipaddresses/

    its in the API doc page 106. Of course you will need first to the ID of the pool. Let me know if you need help with the steps.

    HTH,

    Roland

  • How to open a port and limit the range of addresses that use it on PIX 515?

    I have a Pix 515 v6.3 and a new piece of software that I'm getting soon need aura 5080 open port for incoming & outgoing HTTP traffic. The server will be in my DMZ to 10.0.0.1

    I would like to restrict inbound access to this port so that it can be used in 4 specific IP adderess foreign xxx.xxx.xxx.24 through xxx.xxx.xxx.27 and also, if possible, limit the outbound destination using this port to a single specific foreign IP address xxx.xxx.xxx.30.

    Could you please tell me the best way to do it.

    Thank you in advance for a relative novice to PIX.

    PIX (config) # access list acl-outside permit tcp host xxx.xxx.xxx.24 host MyWWWPublicIP eq 5080

    PIX (config) # access list acl-outside permit tcp host xxx.xxx.xxx.25 host MyWWWPublicIP eq 5080

    PIX (config) # access list acl-outside permit tcp host MyWWWPublicIP eq xxx.xxx.xxx.26 host 5080

    PIX (config) # access list acl-outside permit tcp host MyWWWPublicIP eq xxx.xxx.xxx.27 host 5080

    PIX (config) # access - group acl-outside in interface outside

    PIX (config) # access list acl - dmx permit tcp host 10.0.0.1 xxx.xxx.xxx.30 eq 5080

    PIX (config) # access - group acl - dmz dmz interface

    static (inside, outside) MyWWWPublicIP 10.0.0.1 netmask 255.255.255.255 0 0

    See also:

    PIX 500 series firewall

    http://www.Cisco.com/pcgi-bin/support/browse/psp_view.pl?p=hardware:PIX & s = Software_Configuration

    Configuration of the PIX Firewall with access to the Mail Server on the DMZ network

    http://www.Cisco.com/en/us/products/HW/vpndevc/ps2030/products_configuration_example09186a008015efa9.shtml

    sincerely

    Patrick

  • Delete and re-create a Service profile using the same address (HBA WWNP) WWNP pool

    Hi guys,.

    I have 8 services created profiles used by esxi boot via SAN. The cause is via SAN boot is very important for me the address of WWNP HBA.

    Now, I need to change the model vNIC used in these services profiles to include the option of the VM in the target.

    But for this I have to delete and recreate the model vNIC.

    I think that the UCS will not allow me to that I have unlink and delete the profiles of 8 services (I may be wrong)

    My question is.

    After I deleted a service profile, what is the best way to ensure that new services profile will be used the same address (HBA)

    used by the deleted profile service. ?

    Thanks in advance,

    My best regards,

    Hey,.

    I don't know why you need to remove the 8 SPs when changes (deletion) are on the vnic/HBA model.

    Address WWNP is being derived from a pool? right?

    What is the order of assignment? Default or sequential

    is this specific to only those 8 servers WWPN pool?

    I did a quick test when I remove model HBA he doesn't remove the vHBAs configured in MS.

    Thank you

    -Slim

  • 2821 ACL for the range of IP addresses

    We use an old Cisco 2821 on the edge of the internet for the initial incoming traffic filtering.  To try to block some networks of suppliers that are a source of SPAM, we have tried to apply an ACL that included a range of addresses as follows:

    access-list 110 deny host ip 198.20.160.0 0.0.31.255 255.255.255.255

    This command has been shorted to what follows in the running configuration:

    access-list 110 deny host ip 198.20.160.0 all

    The ACL doesn't seem to work, as we have always received spam through on this range.

    Any help is greatly appreciated.

    Thank you for your time.

    Hello

    Your syntax ACL deny only the host 192.20.160.0.

    If you look below

    access-list 110 deny ip host 198.20.160.0 0.0.31.255 255.255.255.255

    You have the source specified as host (198.20.160.0 host)

    destination like any other host (network mask and subnet inalid - 0.0.31.255 255.255.255.255)

    You want to block what subnet or network, gave me a source and destination subnet? . Will be recorrect the ACL

    HTH

    Sandy

  • iPad does not connect to the Wifi on the range 192.168.0. *.

    I have an iPad Mini (ME860BA) on os 9.3.1 that would not connect to my wifi at home.  He began to abandon their studies repeatedly a few months before and then just wouldn't connect at all.  It is on the os 9.3 so I upgraded to 9.3.1 but it did not help.  I was able to connect using a hotspot from my phone but no go on the real wifi. Sometimes it seems impossible to connect and others it seems to connect but without the wifi icon that appear (and internet access). All other devices connect to the House without exception (or question) - it's just my iPad.

    I followed every bit of advice I've found - turning wifi off & on, forgetting network, reset all the network settings, hard reboot, reboot normal, turning airplane mode turn off again, go up the brightness of the screen (odd) and finally I restored my router and the iPad to factory settings.  Nothing worked, so I took him to a store of Apple and waiting for the genius to see me I thought I would try to connect to the wifi and it went all right!  I felt a little silly to start with but they still took a look and said that he had 'something' bad, but they didn't know what.  Their best guess was that it was something to do with password authentication because they are client wifi has no password.  I returned home and disabled the security mode of the router - I have a Virgin Superhub running the 2.4 and 5 GHz primary wireless networks - no amount of adjusting the security modes (remove the password, make visible SSID, change of Protocol) makes all the difference.  However, knowing that it worked on wifi from Apple in the store, I was really puzzled.

    After ages bother with different parameters (especially in my router), I now know why it does not connect to home... My Virgin router to short on a range of address DHCP IP of 192.168. 0. * and my iPad suddenly won't connect unless the beach is 192.168. 1. * or higher.  (It connected OK for 2 years).  It took weeks to find this out, but at least now I can connect.  I turned on the wifi of comments because it uses the gamme.1.  Everything is good, connects the first time, every time!  I have not tried establishing a password (I was so happy, it connected I left because it was... well as I switch on the MAC filtering, for a little extra protection) I could try side password later and if it still connect, I'll update my post.

    My solution is very well when I'm at home but is not going to help if I get the iPad with me - it will be hit & miss if I can get the WiFi also.  Must be set correctly - I see no that it is hardware related, so there must be a bug in the software/firmware.

    Anyone having problems connecting to wifi can try the workaround network comments - at least it will get you.

    Is there a future fix for this?

    Re: iPad wifi suddenly does not save

    Change the range on the router you want to connect to.

  • Had attempted to obtain address DRAM 524288

    During the execution of my program LabVIEW FPGA in ModelSim 6.5 c using external memory FlexRIO PXI-7952R I get the following fatal error in my window of transcription ModelSim

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    # * Note: running
    # Duration: 2412750 ps iteration: 1 Instance: / tb_nifpgasimulationmodel/mainstimulusblock
    # * Note: SendSettings
    # Length: 4863 ns iteration: 1 Instance: / tb_nifpgasimulationmodel/mainstimulusblock
    # * Note: running
    # Duration: 7741500 ps iteration: 1 Instance: / tb_nifpgasimulationmodel/mainstimulusblock
    # * Note: StartDMA_NOW
    # Duration: 7741500 ps iteration: 1 Instance: / tb_nifpgasimulationmodel/mainstimulusblock
    # * Note: running
    # Duration: 11011500 ps iteration: 1 Instance: / tb_nifpgasimulationmodel/mainstimulusblock
    # * Error:
    # ===================================================
    # Error has occurred
    #
    # Reason possible (s):
    #
    # LabVIEW FPGA: Was an error in the LabVIEW FPGA Module.
    #
    # Attempted to access DRAM address 524288
    # For the simulation, the valid range of addresses of DRAM is 0 to 524287
    # Limiting the address in one the following ways may fix the problem:
    #
    # Nested Clip - sharp: access only to addresses within the valid range.
    # Nested Clip - FIFO: limit the total number of elements written to the PEPS of the maximum range.
    # FPGA memory Articles: access only to addresses within the valid range and avoid access to the memory allocated to partitions beyond the maximum range.
    # ===================================================
    # Time: 11930 ns iteration: 1 Instance: / tb_nifpgasimulationmodel/nifpgasimulationmodel_instance/lvfpgasim795xtop_instance/lvfpgasim795xdrammainx/genbank0mig/drambank0controller
    # * Error:
    # ===================================================
    # Error has occurred
    #
    # Reason possible (s):
    #
    # LabVIEW FPGA: Was an error in the LabVIEW FPGA Module.
    #
    # Attempted to access DRAM address 524288
    # For the simulation, the valid range of addresses of DRAM is 0 to 524287
    # Limiting the address in one the following ways may fix the problem:
    #
    # Nested Clip - sharp: access only to addresses within the valid range.
    # Nested Clip - FIFO: limit the total number of elements written to the PEPS of the maximum range.
    # FPGA memory Articles: access only to addresses within the valid range and avoid access to the memory allocated to partitions beyond the maximum range.
    # ===================================================
    # Duration: 11932500 ps iteration: 1 Instance: / tb_nifpgasimulationmodel/nifpgasimulationmodel_instance/lvfpgasim795xtop_instance/lvfpgasim795xdrammainx/genbank0mig/drambank0controller
    # * Fatal: (vsim-3421) value 524289 is out of range of 0 to 524287.
    # Duration: 11932500 ps iteration: 1 process: / tb_nifpgasimulationmodel/nifpgasimulationmodel_instance/lvfpgasim795xtop_instance/lvfpgasim795xdrammainx/genbank0mig/drambank0controller file: nofile
    # Error fatal to a location protected by source
    #
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    In the first two lines, you can see the notes that my test bench is out.

    When I start the FIFO DMA to 'STARTDMA_NOW' process the fifo beginning to buffer, and then my algorithm starts to fill the DDR RAM. This does not appear to be due to a problem to address. My published project will have several megabytes of different memory blocks in size. But for my test bench I ask for a few hundred bytes.

    I use the external DRAM memory manager by default in the LabVIEW project, and the project has all the elements of memory shared equally in time granted round robin the resource manager in the LabVIEW project.

    I managed to reduce my elements of DRAM to the smallest size that LabVIEW will let me. By doing this, I can now write at least two elements of memory before the ModelSim error.

    It seems that LabVIEW is just launch the elements of memory anywhere that he wants in the memory card and it exceeds the capability of ModelSim to simulate accurately.

    Since the elements of memory as small as possible (it is said actual number of items 131072), this won't ever smaller. I seem to be stuck.

    I need to get LabVIEW to adjust the memory card while ModelSim can be read, or that I have to deal with ModelSim to read outside the range of addresses 524287.

    (and in case anyone asks, I'm not address located outside this range. I have only a few items. I guess that the address to which I am interested in is only a pointer and more the beginning of my block of memory allocated that is created for me.)

    Kind regards


  • Identify the computer IP addresses

    Hello world

    How to identify individual IP addresses of the computer and confirm my own? How to identify the geographical region/city of the different IP addresses?

    IP addresses seem to have 9 numbers - XX. XX. XX.XXX - Sign these individual computers / connection and country town?

    This is related to the identification of hackers in my e-mail address. I have a report of log on the activity that reveals different IP addresses - please answer the layman that I am a little IT not aware

    Really appreicate your support and your help with this! Thank you very much!

    Philippe

    Hi Philippe,.

    IP addresses have actually 12 numbers - xxx.xxx.xxx.xxx - but they tend to drop the zeros so it can sometimes fool you.  The following may help: http://en.wikipedia.org/wiki/IP_address and/or http://computer.howstuffworks.com/internet/basics/question549.htm.

    To confirm your address, click on start / all programs / accessories / right-click on command prompt, and then click Run as administrator.  Then type IPCONFIG/all and enter.   It will tell you your IP address and much more on your connections.  Remember, unless you use a static IP address to your ISP (usually very unlikely), so you have a dynamically assigned address, which means that it could be different every time you connect or remain the same over a certain period to the ISP of time but eventually change even in this case.  If the IP address of your ISP is something of a moving target and tying someone requires knowledge of the address and the time it has been used (and the cooperation of the ISP for this address to provide more details, which I imagine will be difficult to achieve without a court order or something like that).

    You can find information about the owner of an IP address (address may not be the specific but more probably the range of addresses that includes this specific address) using WHOIS.  Here is a place which provides that: http://tools.whois.net/whoisbyip/.  Here's another option: http://www.whois.sc/.  You can find other just Bing search and grabs 'whois' as a search term and you will have more than you can imagine.

    For geographically locating an IP address, do the following: http://www.geobytes.com/ipLocator.htm?GetLocation.  Here's another option: http://www.ip-adress.com/ip_tracer/.  Other alternatives, search for 'The IP address index' Bing and you'll still find plenty of options.

    If you have an email from pirates, you can optionally use the following to follow them: http://www.ip-adress.com/trace_email/.

    Once you know who owns the block of IP address or the address itself, you can then contact them to see if you can find a more about those specific you interest if you also have the exact dates and at the times that go with them--but I frankly don't think that they will provide you information without a court order.

    In addition, there are there programs that can be used to hide your IP address or send a false IP address and most of the pirates, using such programs, so even if you try to track it down, you can discover that they have covered their tracks with several false IP (sometimes several dozen) of their own IP address real than you see in the emails addresses and try to track down who is formidable , even for professionals.

    I recommend you visit the site next where the Government helps people who have been victims of computer-related crime: http://www.ic3.gov/complaint/default.aspx.

    I hope this helps or at least gives you a head start on your quest.  To be honest, the chances to really find these people without being a hacker yourself or hire a hacker are pretty slim, but you might get lucky and if you decide to report it or get help, the more information you can provide, more opportunities they have to do something.

    Good luck!

  • DHCP server press PowerConnect 28xx series / address pool by VLAN

    Hello

    I am reading the manual of the PowerConnect 2824.

    I am considering buying this switch, but I have a question related to the functionality of the DHCP server.

    Here my question: I want to have different VLAN and use the feature of DHCP server on each of them. Then can I have different address DHCP pools by VLAN?

    Example:

    1-16 ports VLAN1: IP subnet 192.168.1.0/24

    VLAN 2 ports 17-24: IP subnet 192.168.2.0/24

    The manual is not clear on this.

    Your help is welcome.

    Kind regards

    Tom

    Daniel,

    Thanks for the reply. Another question does this mean that the 28xx series switch DHCP server, recover the IP address (from the range configured) on all the VLANS configured? So if a device on VLAN 2 issued a request DHCP, it will get an IP address from the same pool as for example a device on VLAN 1.

    Kind regards

    Tom

  • VCS called Ip address routing

    Hello

    I have a question about my VCS control configuration.

    In my scenario, I have control of Vcs and Vcs Express Way.

    I implemented the rule in VCS control:

    .. .the problem: same end point not working with a record keeper and only receive an IP calls. The ip call go all in internet (from the Expressway)

    -----------------------------------------------------------------------------

    Source: AllZones

    Mode: All IP addresses

    On correspondence: continue

    Target: Path (VCS Express Way area)

    ------------------------------------------------------------------------------

    If I call a point of endpoints in the Internet, everything works fine, but if I have to call via ip address, endpoint Internel network (with ip address 10.x.x.x), he call go Express Way.

    I want to put in the control of VCS, rules that use the direct dial plan for all internel ip address (which begins 10.*) and use the indirect numbering plan for the call "unknow ip address."

    Thanks for your help

    FCostalunga

    Hi FC,.

    You can solve this problem by creating a subarea on the VCS control where the subzone membership rule contains subnets with the range of the IP intern (s). For subareas containing the IP address ranges, IP addresses that fall within these ranges is considered known to the VCS, and when endpoint composed one of these addresses IP control VCS will try to set up the call to the IP address itself rather than attempt to transmission by proxy, the call through highway.

    To do this, you must also a rule of search "AnyIPAddress" on your VCS control that points to the local area.

    For reference, I recommend you read through the "Component IP" section in the Administrator's guide from the VCS for X 7, which explained further on the subject.

    Out of curiosity, why you prefer calling IP addresses rather than h.323/SIP URI?

    Hope this helps,

    Andreas

  • MULTIPLE ADDRESSES ON THE EXTERNAL INTERFACE IP

    Hi all

    We put in place a number of ASAs for use with corporate VPN. When remote users connect using anyconnect they can hairpin on the Internet from Headquarters and must assign a public IP address for this purpose. To avoid people getting the same public address every time they go to the internet, we want to set up a pool of public addresses which will be awarded at random to the user of the VPN. Also, for their incoming connection requests, we have a ddns that solves a unique ip address for incoming connections. So, in summary clients connect to a single IP address on our ASAs, then hairpin at the internet and receive a public IP address from a pool. Look at us a few options to do so, but would appreciate any suggestions as to how best to achieve this goal.

    Thank you

    Hello

    It seems to me that the order of the chosen one NAT IP address of the NAT pool is random. I tested on my home with a pool of public addresses small ASA5505.

    I don't know if there is difference between different levels of Software ASA or rather the NAT configuration format. Since the 8.2 (and below) and 8.3 format (and more recent) is completely different.

    If we guess you configure NAT pool for VPN Client users connected to the ASA then configurations need you so

    Software of 8.3 and above

    permit same-security-traffic intra-interface

    object-group, network VPN-POOL

    Description the user VPN address Pools

    object-network 10.10.10.0 255.255.255.128

    object-network 10.10.20.0 255.255.255.128

    network of the PUBLIC-POOL object

    1.1.1.1 range 1.1.1.254

    interface of VPN-POOL PUBLIC POOL dynamic NAT (outside, outside) after auto source

    8.2 software and below

    permit same-security-traffic intra-interface

    NAT (outside) 200 10.10.10.0 255.255.255.0

    NAT (outside) 200 10.10.20.0 255.255.255.0

    Global 1.1.1.1 - 1.1.1.254 200 (outside)

    Global 200 (external) interface

    I don't know what is the amount of your user, but I guess you don't such a pool of important public addresses for users. The configurations above also contain a dynamic PAT when the NAT pool runs out.

    Is that what you're looking for?

    Hope this helps

    -Jouni

  • How can I enter a range of IP access codec C40 using RemoteAccess allow?

    Hello

    I'm setting up a codec C40 running Software 6.1.

    I want to limit systems that can access the codec through SSH/HTTP etc. and found authorize RemoteAccess under Configuration > System Configuration > network

    I want to enter a range of addresses (192.168.2.1 to 192.168.2.254) but may not work on the syntax to do this. The Administrator's guide and QAnywhere mention that ranges are supported but only provide examples for specific hosts.

    Can anyone help?

    Hello

    I think that the command affects the iptables on the codec which is a linux-based system.

    For the 192.168.2.1 to 192.168.2.254 range you might have to specify the following:

    xConfiguration network 1 RemoteAccess allow: "192.168.2.0/24.

    I tried this on my system:

    xConfiguration network 1 RemoteAccess allow: "144.254.10.0/24."

    Then the iptables show entry suite:

    [dderidde-ex90-home: / var/log/eventlog] $ iptables - n list

    INPUT string (policy ACCEPT)

    target prot opt source destination

    Admin channel (1 items)

    target prot opt source destination

    ACCEPT all les--144.254.10.0/24 0.0.0.0/0

    Drop tous--0.0.0.0/0 0.0.0.0/0

    That should do it I think.

    Danny.

  • How to change the local IP on the virtual NETWORK adapter for Web server address

    Hi all

    I have a physical Windows system, on which I run VMware Workstation 9. Now on VMware I run Ubuntu 12.10 a LAMP for a Web server.
    Problem:
    Now, my local IP address for my NETWORK card virtual (using the Ubuntu one) at the address 192.168.159.7 and my router only emits the 10.0.0.x range IP addresses. So if I want to port forward to the virtual NETWORK adapter that has a 192.168 address, I can't, so my LAMP Web server are not accessible to the outside because the router does not send packets on port 80 to the virtual card... How to fix this?
    The only way I guess that is to be assigned an ip address of 10.0.0.x to the virtual NETWORK adapter?
    But how do I do this?
    I tried to do it on the host from the Windows machine with "get my IP address automatically", but she emits an 192.168 address every time...
    Thank you

    Welcome to the community,

    I guess that the virtual computer is currently configured to "NAT" or "Host-Only' networking! That would explain the 192.168.x.x IP address.

    There are 2 options to be able to access the web server on the virtual computer.

    1. with "NAT" network configured

    In this case forward port 80 to the IP address of the host and configure the port forwarding on the virtual computer in the "Virtual Network Editor. This way you can leave the IP address on the private network of 192 (if it is currently set to NAT)

    2. use "Bridged" network layout

    Reconfigure the virtual NETWORK adapter to the machine virtual networking "Bridged" within the parameters of the virtual machine, assign an IP address from your router network (10.x.x.x) and do the port forwarding on the router directly to the IP address of the virtual machine.

    André

  • authentication based on the host: < - address of the host > is ignored

    Hi guys,.

    I try authentication based on the host to the cluster nodes. but the nodes are not authenticated at all, even a knot on a host not specified in the configuration is joining the cluster and newspapers are absolutely perfect. Can't understand why <-host address > is ignored?

    Here is my config:
    <coherence xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://xmlns.oracle.com/coherence/coherence-operational-config"
         xsi:schemaLocation="http://xmlns.oracle.com/coherence/coherence-operational-config coherence-operational-config.xsd">
    
         <cluster-config>  
         <unicast-listener>
                   <well-known-addresses>                 
                      <socket-address id="1"><address>10.152.21.52</address><port>31760</port></socket-address>
                      <socket-address id="2"><address>10.152.21.53</address><port>31760</port></socket-address>
                      <socket-address id="3"><address>10.152.21.54</address><port>31760</port></socket-address>
                        <socket-address id="4"><address>10.152.21.55</address><port>31760</port></socket-address>
                 </well-known-addresses>     
         <address>localhost</address> 
               <port>31760</port>         
             </unicast-listener>      
         <authorized-hosts>               
                         <host-address id="1">10.152.21.52</host-address>
             <host-address id="2">10.152.21.53</host-address>
             <host-address id="3">10.152.21.54</host-address> 
                    <!-- <host-range>
                         <from-address>10.152.21.52</from-address>
                         <to-address>10.152.21.55</to-address>
             </host-range> -->
         </authorized-hosts> 
           </cluster-config>       
           <configurable-cache-factory-config>
                <class-name>com.oracle.coherence.environment.extensible.ExtensibleEnvironment</class-name>
              <init-params>
                          <init-param>
                              <param-type>java.lang.String</param-type>
                              <param-value>ccoe-cache-config.xml</param-value>
                          </init-param>
                </init-params>
             </configurable-cache-factory-config>
    </coherence>
    However, if I use <-host range > instead of <-host address > it works quite well and trying to reach any node a host outside the specified range cluster it gets and exception 'this member is not allowed to join the cluster' as expected.

    Any ideas why <-host address > is completely ignored? I'm misssing something stupid?

    Thank you
    D

    Hi D,

    It looks like a bug in consistency for me due to the fact that the tangosol - default coherence.xml file contains an empty host range in the section authorized hosts. Even if you overloaded authorized hosts this empty beach is always included in the Cluster configuration, then the class that reads this part of the configuration is messed up.

    Specifically, in your case, the XML from your substitution file combined with the default settings in tangosol - coherence.xml would look like this...

    
        
            
            
                
                
            
            10.152.21.52
            10.152.21.53
            10.152.21.54
        
    
    

    .. .who processing does not create a filter to authorized hosts.

    Here's a test case...

    String XML = "" +
            "    " +
            "        " +
            "        " +
            "            " +
            "            " +
            "        " +
            "        10.152.21.52" +
            "        10.152.21.53" +
            "        10.152.21.54 " +
            "    " +
            "";
    
    XmlDocument xml = XmlHelper.loadXml(XML);
    LegacyXmlClusterDependencies deps = new LegacyXmlClusterDependencies();
    deps.fromXml(xml);
    Filter authHostsFilter = deps.getAuthorizedHostFilter();
    // Oops... authHostsFilter is null!
    

    If you delete the Virgin beach of the XML in the test and run again you get a filter.

    JK

    Published by: Jonathan.Knight on February 8, 2012 11:55

  • Unknown Apple IP addresses in the ARP table?

    Given that I added two Apple TV 4 to my network via ethernet and using IP addresses static, I notice several entries in an IP scan for unknown IP addresses that seem to be related ATV equipment.

    I am at a loss for why this is happening or how to fix it.  I unplugged my ATV gear and restarted the routers and switches, emptied of the ARP protocol on mac I use to scan ports, but registrations continue to show.

    It is an example of what I see.  Appreciate any ideas or suggestions.

    Name: Inactive device, device Type: other, IP: 192.168.1.176, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.102, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.104, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.105, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.113, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.126, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.128, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.129, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.137, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.143, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.145, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.146, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.147, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.148, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.156, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.157, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.158, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.160, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.162, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.175, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.177, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.178, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.179, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.181, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.182, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.183, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.184, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.185, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.186, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.187, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.188, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.189, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.190, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.191, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.192, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.193, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.194, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.195, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.196, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.197, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.198, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.199, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.168, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Name: Inactive device, device Type: other, IP: 192.168.1.169, MAC: UNKNOWN, IPv6: UNKNOWN, DNS: UNKNOWN, manufacturer: Apple, Inc.., last seen: 24/04/2016-09:49:52

    Strange. We'll see.

    You have configured your DHCP router in order to exclude the static address of the DHCP pool? Why use static addresses, anyway? Are the addresses reported in DHCP pool?

    You have configured the static addresses in the ATV? As well as the correct values for the gateway and the server names?

    These are obvious questions, but need to check.

    They are all the last time at the same time, which I suppose is the time of the scan. It would simply mean their leases have not expired. What is your DHCP lease?

    Do you use the wifi for devices that come and go? This could explain some distribution of values of intellectual property.

    Do you use AirPlay to a device on a wifi network for an ATV on another network? In other words, you need bluetooth to make AirPlay work?

Maybe you are looking for