The 'work around' here is to add the FQDN of THIS system (e.g.
Kt1.litmus.com <http://kt1.litmus.com/>) that would for me on the outside
resolve to 9.4.0.10 into the hosts table pointing to 192.168.1.10 on that
server only.

Bingo. I also needed to change CFGTCP opt 12 to be HOSTSCHPTY(*LOCAL) as
it was *REMOTE. I thought I had RTFM(n1) close enough, but it turns out
skimming failed me this time. Thanks again, Larry.

n1 -
http://www-01.ibm.com/support/knowledgecenter/ssw_i5_54/cl/addtcphte.htm?lang=en

Aaron Bartell
litmis.com - Services for open source on IBM i


On Tue, Jan 19, 2016 at 10:51 PM, DrFranken <midrange@xxxxxxxxxxxx> wrote:

This will depend on the firewall you are using for sure. Cisco devices
will not allow this. You are sending traffic from (Say) 192.168.1.10 (its
private IP Address) that routes in some way to the firewall. The firewall
then NATs that to (say) 9.4.0.10 (its Public IP) That traffic is now on
the outside interface of the firewall. However that traffic is destined for
that same IP address which shouldn't be a problem except the source and
destination are the same and on the same interface. A Cicso firewall for
one will not allow that traffic to return back through NAT and back to the
private IP (192.168.1.10) so you'll never connect.

I believe some firewalls WILL allow this and I wouldn't be shocked to find
there is some hairpining setting that might allow this but it's generally
not best practice.

The 'work around' here is to add the FQDN of THIS system (e.g.
Kt1.litmus.com) that would for me on the outside resolve to 9.4.0.10 into
the hosts table pointing to 192.168.1.10 on that server only.

- Larry "DrFranken" Bolhuis

www.Frankeni.com
www.iDevCloud.com - Personal Development IBM i timeshare service.
www.iInTheCloud.com - Commercial IBM i Cloud Hosting.



As an Amazon Associate we earn from qualifying purchases.

This thread ...

Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.