Skip to main content

Posts

Showing posts from July, 2012

Ports requirement for routing protocol to work behind firewall.

Port to allow Routing protocol to work behind firewall. I.Enabling RIP A. RIP version 1 RIP runs over UDP port 520. It sends and receives all messages on this port; all messages are sent to the local broadcast address. To enable RIP, add a rule to allow all a firewall's neighbors to send messages to UDP port 520 on the local broadcast network. RIP is a predefined service in the Security Gateway GUI. Source Destination Service Action Track Install On Neighbor 1 Network 1 Broadcast RIP Accept Gateways Neighbor 2 Network 2 Broadcast RIP Accept Gateways Neighbor 3 Network 3 Broadcast RIP Accept Gateways B. RIP version 2 RIPv2 can use either the RIPv1 broadcast transport mechanism, or a multicast transport (RIP2-ROUTERS.MCAST.NET, 224.0.0.9). To enable RIPv2 in multicast mode, create a workstation object for the multicast address, and add the following rules to your rule base: Source Destination Service Action Track