Management of the external/DMZ switch

How do you suggest I manage external switches to a firewall. We have a switch on the outside of our firewall I want to be able to connect to SNMP and also use GANYMEDE, NTP, remote syslog, etc.. It would be preferable to give IP in the physical (read: external) subnet, or put one of the ports in a vlan separate and connect to this port to the segment internal. It seems as though this is precarious, because he crosses boundaries, but I'm not sure. Thank you.

Hello

As you mentioned on the firewall to the outside, the minimum configuration is a switch connecting your firewall outside interface for external devices like the router boxes and internet vpn.

Side of the firewall, you need the static NAT address GANYMEDE, NTP, SNMP, syslog server to a public IP address to be accessible from the outside, more precisely by the switch. Create an ACL (or add existing) strictly for the switch (via its public IP address) to specific services such as GANYMEDE (tcp 49) / NTP(udp 123) /SNMP (udp 161/162) /Syslog (udp514) to your internal servers.

On the side of the switch, you can public IP address assigned to the switch with all authentications by default points to the public IP of the internal server to GANYMEDE (NATted in the firewall). Your aaa configuration should point to your internal ACS server.

Recommendation of Cisco switch, especially when you placed it outside the firewall, is more or less similar to the steps to secure your router. He talks about securing access to the box, services management/limit flooding, etc. Read the Cisco documentation on how to secure the router for a reference:

http://www.Cisco.com/en/us/Tech/tk648/tk361/technologies_tech_note09186a0080120f48.shtml

http://www.NSA.gov/SNAC/downloads_cisco.cfm?menuid=scg10.3.1

Rgds,

AK

Tags: Cisco Security

Similar Questions

  • Missing labels of power management on the external keyboard, wireless mouse, wireless mouse, all different brands

    On my laptop HP HDX18 only the touchpad and keyboard have power management tab to enable them to wake the computer.

    My external keyboard of Firefly, wired Kensington mouse and Logitech wireless mouse all have not the power management tab. I wrote to Logitech about this and they said that I needed new ACPI/USB drivers. I installed the latest Intel chipset drivers I knew from the updated HP drivers website.

    HP told me that it is normal, current is cut for USB hubs. Which is ridiculous. I have disenabled the selective suspend for the USB ports under settings in Device Manager and power went to each USB hub and unchecked "allow the computer to turn off the power of the device", which can be the meaning of HP. I have the latest version of the BIOS. But still no power management tab is displayed.

    Hi Oldroser,

    Please see the article regarding your question:

    http://Windows.Microsoft.com/en-us/Windows-Vista/troubleshoot-power-problems

    I hope this helps!

    Debra
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think

  • Out-of-Band management on the servers in the DMZ

    Hi, I have four PC7048s in my DMZ. External, internal making face and 2 separate demilitarized. Everything is good. All workers.

    Since they are demilitarized I want only their route between them and thus in position off http, Https, Telnet, and SSH management so that they cannot be managed remotely from the DMZ subnets.

    I then plugged the OOB interfaces in my internal management switch and VLAN them accordingly. Very well, now I can ping my OOB interfaces on all four. But I can't manage them because I have disabled SSH, HTTPS, HTTP and Telnet

    If I allow them (just SSH and HTTPS) I am now able to manage the switches of the DMZ on the IPs DMZ subnet

    I thought that the point of the OOB was so this does not happen and there is isolation? If I have to spend globally on HTTPS and SSH, then they are not really well isolated (I understand that OOB traffic cannot talk to IN-Band etc. - is the fact that I turn on a global configuration for remote OOB service)

    Am I missing something?

    Thank you

    Your results are correct. To lock the management more far I suggest looking to implement ACLs. With the ACL you can permit/deny access to various management services.

    Page 1471, guide the user passes over these commands.

    FTP.Dell.com/.../PowerConnect-7048r_Reference%20Guide_en-US.pdf

    Thank you

  • Tecra S2 cannot switch to the external display

    With my Tecra S2 and when it is docked in the Port Replicator APR - III, I used to be able to connect my external (via DVI) display so that it was to automatically screen output to we by default, not only to the windows startup screen (Yes, I noticed the topic on the forum at the start of windows) but also when display login screen and beyond.

    Only problem now is that there is no more than anything, she now only sends the output to the external display when starting and then switches back to the computer screen displaying the screen Windows login and when you are connected to Windows.
    Also after commissioning and connection, FN + F5 does not at all, even when you switch to DVI, display does not illuminate.

    I feel that either the nVidia properties settings (double screen, unique, etc.) or the Mobile Extension Manager have something to do with it.
    Anyone who knows the answer / solution to this problem?
    Experts on the Mobile Extension Manager or several monitor in nVidia settings with of Toshiba Tecra?

    Thank you

    Arjen

    Hello

    Well, as I know it is not possible to set the external monitor as a default monitor.
    I use a Satellite phone and sometimes I plug it into the external monitor and use the extended desktop option.
    During notebook startup procedure the windows boot image will appear on the second screen, but the user name and the operating system appears on the screen of the laptop.
    I think you can use the external monitor but you can't set it as a default monitor and you can use it if the operating system has been released.

  • Portege R700 with docking station may not automatically switch to the external display

    Hello!

    In the past, we bought a lot of A600, R500, S10, and always a docking station for every laptop here at Desjardins, we bought.

    Now we have a little problem with the new R700 model: PT318C - 00G 001,
    We bought 30 of them.

    WHY when we put in the tie-down (with the nearby screen) it can display automatically to the external display no/switch? (in this case a 22inc LCD)
    It is connect with the HDMI/DVI cable. And when we get the display by sliding in the graph of intel and media panel (V 6.14.10.5258), after a reboot of the docking, the screen is all buzzy... sometimes both screen are dark, and we must use a combination of keys to move.
    It's really not easy to use for our users...

    With the old model as the A600 or S10, all have always worked well, if we are on the dock, the pop screen directly on the external LCD, so I stopped him, ondock it and start up of all is well on the screen of the laptop.

    We are on Windows XP Pro SP3.

    I tried the utility Toshiba display device change and expansion Mobile from Toshiba. are not clear...

    Thanks for your help.

    Have you installed a version of vanilla from Windows? Or XP has been installed from the Toshiba Recovery Disc?
    Maybe you are missing several key structural factors (common modules for example). Also make sure that you use the drivers to display on the Toshiba site.

    Also try a BIOS update (v1.70 is the last one I think).

  • Does not work on Tecra A2 - FN or key how to switch to the external display?

    Hello

    Tomorrow (Saturday 6) I have to show a little presentation my Tecra A2 on an external display or projector.
    After that I have to install my laptop for the second time last month, the Fn or function keys do not work.
    With this problem I don't know how to work with the external display.

    Please can you advice?
    Sorry for my English at low altitude.

    Buist huh
    The Netherlands

    @J.Verberk
    Sounds you're a newbie and you're talking nonsence
    You comment is simply not qualified.

    @Hein
    You said that you have installed you mobile again. Did you use the Tosh recovery CD?
    If this isn't the case, I think this might be a reason for the FN key anomaly.
    After recovery use the laptop must switch with FN + F5 external peripheral connected to the laptop.
    If you use try beamer to turn the trap settings.

  • Hi all. How can I manage the preferences that LR do not take up space on my MAC hard drive and works only on the external hard drive?

    Hi all. I am new and on a free trial right now.

    How can I manage the preferences that LR do not take up space on my MAC hard drive and works only on the external hard drive?

    Monthly payment included cloud storage?

    Peut I manage backups? And how?


    -Amir

    Hi amireos,

    Yes, you can create your workflow where you can keep all your images on the external hard drive and the Lightroom catalog file as well.

    If you start with Lightroom and then use the Destination location as external hard drive when you import your image of the external source such as a camera or SD.

    If you already have your Images on the Mac HD drive, then play all your Image on the external hard drive first and then import images directly from there.

    Finally, you can change the location of the Lightroom Catalog as well.

    Default location: folder on the Mac Drive HD, there is folder called Lightroom that you can move on the external drive too (however catalog Lightroom can't memory space as its only import previews of the images is not the real image and full)

    Once you move the file catalog Lightroom external hard disk, then you need to browse the catalog file when you launch Lightroom only once.

    See thread: LR catalog moving on external hard drive

    Let us know if it helps.

    Kind regards

    ~ Mohit

  • Switching the external display to MBP screen retina, poor quality, need to restart FF19.0.2

    Here is the chronology of the events:

    (1) FF start on my MBP (OS 10.8.2) and the retina display working properly.

    (2) connect my MBP to a 24 "external display which has a resolution of 1920 x 1200 (defined as primary) max. FF displays well on screen.

    (3) disconnect the external display and FF is now pixel on retina MBP. Updating of system preferences Dispay doesn't seem to help, or I have not found the magic technique.

    (4) restart FF and everything is fine.

    The question seems so FF not to recognize the need to revisit the resolution of the retina.

    You are welcome

  • Aero off when the external monitor is turned by Nvidia ControlPanel

    Please see subject
    Aero works perfectly when the office is developed for the 2nd monitor in normal mode.
    no work around?

    Post edited by: mhoffmann

    Sorry, I forgot to mention my hw: Satellite a100-02 b (geforce go 7600)

    .. and when I reboot Vista behaves a little bit strange.
    a few seconds, everything looks ok, but then it redefines the external monitor to 16-bit color and minimum Vfrequency (60 HZ)
    and a message appears that the 'Desktop Manager' was closed due to a problem.

    Maybe it's because...
    (1) it is an old CRT, not especially known (standard pnp driver)?
    (2) the ability of the graphics card vista is not sufficient in this configuration?

    I heard somewhere that there is a switch in the registry, which disables the dwm.exe test, if the material is
    able to support the aero technologies. What is a way to fix it?

    Hello

    I read about the registry hack that allows the function Aero Vista on graphics cards that are generally not able to manage the Aero feature.
    But I don t think that the modified registry key might help with this problem!

    In any case, I try to understand what you were doing on the laptop
    You have turned on the display on the second external monitor, then you have changed the position of the screen (you turn the display) and you tried to use the Aero on the external monitor.
    Am I wrong?

    Well, what to say, it s not easy to say if she s a problem or just a limitation of Vista Aero.
    I have never tested or used Aero after the display has been set at another position.

    I think you should test Aero on external monitor without rotation.
    Please also see this Toshiba knowledge base article on

    What are the requirements of Aero in Windows Vista?
    http://support.toshiba-tro.de/KB0/TSB7101O90002R01.htm

  • activate the external clock

    Alrighty, I'm a total noob to LabView and others. I'm at the point where I don't even know if I know is relevant, so forgive if I give too much information and probably not enough.

    I've got:

    cDAQ-9174 chassis

    9422 module into the connector #2

    This 9422 module will be connected to a meter that will send a square wave. What I need is the frequency of the square wave. Problem is, I don't have any idea how to get it.

    I open a new .vi and use the DAQassist. From there I select entry counter and then I tried the frequencies and Edge Count.

    At the end of the day, either it usually gets me the following error message:

    Error-200284 occurred to...

    Possible reasons:
    Some or all of the requested samples are not yet acquired.

    I guess that one I did most of the research is the counting of edge. It is continuous samples because I need to monitor the flow rate at the time rather than only to count the edges of time 0 until I stop the VI. So there are different ways to treat this error include changing the timeout value, something to do with 'samples to read' and 'sample rate', and then that it seems to me that I have to do: since the buffered continuous one requires an external clock, which is specified in the tab "Advanced Timing" of the menu properties DAQassist I have a lot of things to choose from. It seems/I/SampleClock or/ao/SampleClock is the thing to choose, but then several Web pages continue to say to make sure that the external clock is actually "run", or any word in this sense. So I tell myself, my external clock isn't doing anything and that's why reading isn't acquire samples. But really, I'm just lost. Then...

    Question 1:

    Is what I'm working on the best/right way to go about doing this?

    Question 2:

    How can ensure me that this external clock done everything what it is supposed to do so that I can get samples still for edge counting?

    Well, my ignorance is exposed, please fire away. I have attached the .vi, although I don't think it will tell you anything other than I know how to click the mouse button when running LabView.

    County Board is time since you don't have a sample clock.  You can provide one from many sources, but in your case I suggest sticking to a task of frequency measurement I won't go into it now.

    The frequency could be time for a number of possible reasons:

    1. the external signal is not connected to the right Terminal (the default IS terminal your meter chosen if you not him have not overridden with a property DAQmx node which is not possible in the DAQ Assistant).  For the 9422:

    2. the signal may be connected to the right Terminal, but perhaps, it does not meet the specifications of the 9422 to be detected)<5V low,="" 11-60v="" high).=""  you="" can="" verify="" whether="" or="" not="" the="" signal="" is="" being="" detected="" using="" a="" test="" panel="" (counter="" edge="" counting="" to="" determine="" if="" the="" signal="" is="" present)="" in="" measurement="" and="" automation="">

    3 tasks of frequency are sampled off the input signal - so if the input signal does not switch when you start the program or if there is a long break (longer), you will receive the time-out error when the reading function blocks for more than your specified time-out.  You should be able to just 'manage' the time-out error so that if it happens you can report a frequency of 0, ignore the error and try to read it again.  There are also other approaches such as using events DAQmx or samples available to read to vote, but none of them are available through the DAQ Assistant (the idea is that you avoid making DAQmx Read blocking call until you know there are samples to read).

    Configure a task of frequency is a better option for you, because it will give more precise (although you can set a task of County of edge to behave similarly to a frequency measurement task, this is trickier and you can also use the DAQ assistant).  You can start out by setting 1 sample (on request) for the synchronization mode - this will return a single sample as soon as it is available.  If you put the DAQ Assistant, in a loop, you will get a new sample at each iteration (or if your input signal goes, the samples will stop coming in and you'll get time-out errors instead).  The downside is that you will not receive a sample on each side - entry task is reset by software and during this downtime between the samples will take no new data.  This should be good for the case of the use you described (the frequency of a continuous square wave periodically monitoring).

    So, make sure that the external signal conforms to the specifications of the 9422, and it is connected to the correct terminal (the PFI line which is equivalent to the DOOR of your meter by default).  If your external signal is less than 0.2 Hz (1 sample every 5 seconds) you will need to move away from the DAQ assistant, as it seems that it is not possible to set the timeout of read using the DAQ Assistant (surprisingly).  You might want to look in the API of DAQmx lower level anyway - here is a simple example to help you get started in the affirmative.  It's really not too complicated and once you get used to it will be less heavy than using the DAQ Assistant.

    Best regards

  • Turn off display when you use the external monitor R61?

    Hello

    I have a ThinkPad R61, which I use with an external monitor.  Somehow, I had in place for months with the laptop out of the screen and the monitor on.  I've used today at a meeting to feed a projector, selected somehow dieting Fn F7 of presentation such as the screen and the projector are-as I wanted - then home, re-installed with my external monitor and cannot find out how to turn off the display on the laptop.  The selections under Fn F7 do not allow this combination.  I tried the trick you offered, Fn F3 to turn off the display, but it turned out the two views.  (Now, how can I reverse this setting?)

    It sounds like a requirement of switching every day, but I can't find a clue in aid of ThinkVantage, manual mini, on the website, etc.  Thank you

    WaynO salvation,

    After pressing Fn + F7, click on manage plans... to open the Director presentation window. Then click the new... button. You should be able to put in place a system to only display on the external monitor. After setting up, make sure to check the box in the column Menu Fn + F7 to have your new schema appears in the menu when you press Fn + F7.

  • How to use the book of fonts with fonts that are installed on the external hard drive

    I have all my fonts to a folder on an external hard drive. How can I use font book to manage these fonts? I want to keep on the external hard drive, not book fonts move them to my main hard drive. For some reason, font book does not know where are the fonts and as soon as I show, he sets in motion all the fonts on my hard drive in a folder/library/fonts. NOT what I want! I don't want thousands of fonts clutter up my main hard drive. I just can't understand how the font book. Only option, I can see, it is 'Install' and it is then the copy begins. I read and tests all day and I just can't understand this. Thanks for your suggestions.

    Font book handles only the fonts that are present in one of the folders of fonts on the startup disk. It can disable these fonts, but it won't work as a custodian of the fonts installed also. I would have suggested using a symbolic link to the folder fonts on the external drive to ~/Library/Fonts, but apparently that no longer works: allow to use symlinks in ~/Library/Fonts

  • Interruption of the external connection USB - C display after sleep

    I connect my MacBook (retina, 12 inches, beginning 2016) directly via a USB - C cable for an external display Lenovo X 1. The MacBook recognizes the display when I plug in the cable. I then close the MacBook and work exclusively in the external display. However, after that the MacBook wakes from sleep, he does reconnect not to display. This means that whenever the computer goes to sleep I have to disconnect and freshly plug cable USB - C to connect to the screen. Anyone know what to do the display remains connected?

    Hello forestforger,

    Thank you for reaching out to the Community Support from Apple. I know just how you feel. I have a few different external monitors, that I use with my MacBook - I depend on everything working properly!

    One way to solve this problem is by resetting the management system (SCM) controller on your MacBook. MSC helps to regulate the functions of some of the other material on your Mac. This article will guide you through how to reset: reset the management system (SCM) controller on your Mac.

    Let us know if this works, or if you experience other problems, the entire community is here to help.

    Best regards

  • Re: Satellite R630-13F: taken Possible supported the resolution of the external LCD screen

    Hello

    I intend to buy a LCD for my editing work.
    My laptop is R630-13F.

    I was wondering if I get the LCD high resolution (2560 x 1440), my phone would support such screen? Thank you very much.

    Tim

    Hello

    The external screen resolution depends on the graphics card and the external monitor.
    As far as I know the Intel graphics chip that is used in this laptop is capable of managing the max 2048 x 1536 at 32-bit resolution

    2560 x 1440 appears to be too high

  • Connect the external DVD player to Satelite Z930

    Hello world

    I recently bought a Toshiba external dvd drive, which officially supports win7 and Vista (no mention of 8) of the brand.

    The external dvd drive is model PA3834A-1DV2 aka Portable SuperMulti Drive

    When I connect this drive with one or two USB connections (SuperMulti drive has 2 USB connections), there's enough power to the drive eject and spin, but the computer does not display the drive in my computer. It is displayed in Device Manager with a yellow exclamation however.

    Y at - it no formal or informal word there is a way for this device works with Windows 8 on the Z930?

    My apologies if I should have posted this in a different thread.

    Which is really strange. I have the external BD drive and it is automatically recognized by Win7 or Win8.
    You use original Win8 preinstalled that you got with your laptop or you install on your own?

Maybe you are looking for

  • Flex 2 14 Grphics card update

    Hello I use Notebook Lenovo Flex 2-14 59426270 14\"FHD / Core i5-4210U / 8 GB / 500 GB SSHD / GeForce 840 M 2 GB,. I want to improve my GEforce 840 M graphics card, is this possible? and how? I will do som evil to my laptop if I do? Help, please. Tha

  • Sampling frequency for digital sampling (cDAQ-9172 &amp; NI 9401)

    Hello! I have a cDAQ-9172 with NI 9401 C-series (digital) module. I would like to taste the digital inputs with a sampling frequency of e.g. 400 or 200 kHz. My problem is that I can only choose a clock 100kHzTimebase and therefore only get a sampling

  • In labview so I select all items in the drop-down list, the corresponding elements of the need to change page

    as an example of If I select the first item - drop-down box, in the page it should only show digital controls 1 and 2 If I select the second element - drop-down box, in the page it should show only digital commands 3 and 4 If I select the third eleme

  • HP Power Assistant causing audio/video Stutter - laptop Elitebook 8560p, Windows 7 x 64

    Hello I recently noticed periodic audio and video on my new laptop I wanted me to rid of stuttering. I did not notice the stuttering when I bought the computer a few months ago, and if my memories are good it seemed initially after some recent automa

  • Build the release version

    I just upgraded to the latest SDK and momentics after consuming not for a few months. I am now ready to build a version to download, but I don't see the option more.  I could have sworn that under the context menu of the project, under Blackberry too