<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for www.gobien.be</title>
	<atom:link href="http://ares.gobien.be/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://ares.gobien.be:8080</link>
	<description>About computer technology</description>
	<lastBuildDate>Sun, 29 Jan 2012 19:01:24 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>Comment on Netscreen policy based routing cross virtual router by Stan Gobien</title>
		<link>http://ares.gobien.be:8080/2010/04/netscreen-pbr-cross-virtual-router/comment-page-1/#comment-364</link>
		<dc:creator>Stan Gobien</dc:creator>
		<pubDate>Sun, 29 Jan 2012 19:01:24 +0000</pubDate>
		<guid isPermaLink="false">http://ares.gobien.be:8080/?p=89#comment-364</guid>
		<description>Just an update on this.
The client is by now running on an SSG140 with ScreenOS 6 and there I found an option on the trust-vr virtual router to change the preference value of PPOE and DHCP connected interfaces.

In my example this now results in all interfaces being put in Untrust and the statically assigned interfaces has the highest preference. You can still use PBR policies to force some traffic the way you want and you even have automatic failover if an interface goes down (completely down, i.e. disconnected). On ScreenOS 5 there is a problem with VIPS on multiple Untrust interfaces.</description>
		<content:encoded><![CDATA[<p>Just an update on this.<br />
The client is by now running on an SSG140 with ScreenOS 6 and there I found an option on the trust-vr virtual router to change the preference value of PPOE and DHCP connected interfaces.</p>
<p>In my example this now results in all interfaces being put in Untrust and the statically assigned interfaces has the highest preference. You can still use PBR policies to force some traffic the way you want and you even have automatic failover if an interface goes down (completely down, i.e. disconnected). On ScreenOS 5 there is a problem with VIPS on multiple Untrust interfaces.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Call of Duty Modern Warfare 3 port forwarding (NAT type Open) by Stan Gobien</title>
		<link>http://ares.gobien.be:8080/2011/11/call-of-duty-modern-warfare-3-port-forwarding-nat-type-open/comment-page-1/#comment-352</link>
		<dc:creator>Stan Gobien</dc:creator>
		<pubDate>Thu, 01 Dec 2011 20:03:50 +0000</pubDate>
		<guid isPermaLink="false">http://ares.gobien.be:8080/?p=213#comment-352</guid>
		<description>I have exactly these ports forwarded and have since NAT type Open (was Strict before).

Make sure your windows firewall is disabled as well for testing purposes. If that changes things than you can add rules in the windows firewall for the ports above. 

I have the windows firewall just disabled as I trust my home network and NAT blocks any access to the PC from the Internet except for the ports you forward. But never do a full DMZ to a windows PC!</description>
		<content:encoded><![CDATA[<p>I have exactly these ports forwarded and have since NAT type Open (was Strict before).</p>
<p>Make sure your windows firewall is disabled as well for testing purposes. If that changes things than you can add rules in the windows firewall for the ports above. </p>
<p>I have the windows firewall just disabled as I trust my home network and NAT blocks any access to the PC from the Internet except for the ports you forward. But never do a full DMZ to a windows PC!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Call of Duty Modern Warfare 3 port forwarding (NAT type Open) by well</title>
		<link>http://ares.gobien.be:8080/2011/11/call-of-duty-modern-warfare-3-port-forwarding-nat-type-open/comment-page-1/#comment-351</link>
		<dc:creator>well</dc:creator>
		<pubDate>Thu, 01 Dec 2011 14:03:37 +0000</pubDate>
		<guid isPermaLink="false">http://ares.gobien.be:8080/?p=213#comment-351</guid>
		<description>Using this --&gt; NAT : Moderate</description>
		<content:encoded><![CDATA[<p>Using this &#8211;&gt; NAT : Moderate</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ARES The Linux Home Server by Stan Gobien</title>
		<link>http://ares.gobien.be:8080/2007/03/ares-the-linux-home-server/comment-page-1/#comment-75</link>
		<dc:creator>Stan Gobien</dc:creator>
		<pubDate>Sun, 09 Jan 2011 10:37:17 +0000</pubDate>
		<guid isPermaLink="false">#comment-75</guid>
		<description>This information is not up to date.</description>
		<content:encoded><![CDATA[<p>This information is not up to date.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Installed ESXi 4 (with FTP &amp; SSH enabled) &amp; migrated VM&#8217;s from workstation by Stan Gobien</title>
		<link>http://ares.gobien.be:8080/2009/11/esxi-4-with-ftp-ssh-migration/comment-page-1/#comment-74</link>
		<dc:creator>Stan Gobien</dc:creator>
		<pubDate>Sun, 09 Jan 2011 10:34:47 +0000</pubDate>
		<guid isPermaLink="false">http://ares.gobien.be:8080/?p=66#comment-74</guid>
		<description>ESXi 4.1 has the ability to enable remote SSH from the VSpehere Client. Out of the box.</description>
		<content:encoded><![CDATA[<p>ESXi 4.1 has the ability to enable remote SSH from the VSpehere Client. Out of the box.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on GhettoVCB ESX(i) VM’s backup: E-mail logfile by Stan Gobien</title>
		<link>http://ares.gobien.be:8080/2009/12/ghettovcb-esxi-backup-e-mail-logfile/comment-page-1/#comment-73</link>
		<dc:creator>Stan Gobien</dc:creator>
		<pubDate>Sat, 08 Jan 2011 10:08:29 +0000</pubDate>
		<guid isPermaLink="false">http://ares.gobien.be:8080/?p=73#comment-73</guid>
		<description>The latest version of GhettoVCB can e-mail the logfile by itself. As long as you use ESX(i) &gt;= 4.1.</description>
		<content:encoded><![CDATA[<p>The latest version of GhettoVCB can e-mail the logfile by itself. As long as you use ESX(i) >= 4.1.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ares server statistics by Stan Gobien</title>
		<link>http://ares.gobien.be:8080/ares-server-statistics/comment-page-1/#comment-62</link>
		<dc:creator>Stan Gobien</dc:creator>
		<pubDate>Thu, 02 Dec 2010 21:56:10 +0000</pubDate>
		<guid isPermaLink="false">http://ares.gobien.be:8080/?page_id=79#comment-62</guid>
		<description>And munin is excellent for graphing it all up automatically.</description>
		<content:encoded><![CDATA[<p>And munin is excellent for graphing it all up automatically.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Netscreen policy based routing cross virtual router by Stan Gobien</title>
		<link>http://ares.gobien.be:8080/2010/04/netscreen-pbr-cross-virtual-router/comment-page-1/#comment-10</link>
		<dc:creator>Stan Gobien</dc:creator>
		<pubDate>Mon, 31 May 2010 17:16:07 +0000</pubDate>
		<guid isPermaLink="false">http://ares.gobien.be:8080/?p=89#comment-10</guid>
		<description>Hi yasser,
Luckily for me the ADSL PPoE was static. 
Sometimes even with dynamic PPoE connections the gateway always stays the same. If that&#039;s the case for you, then you can follow my example.

If not, then you have a problem.
1) You could put the interface back in trust-vr and find some way to make your statically set gateway a higher priority. I didn&#039;t found out how to to do it, and someone on the juniper forum said you just can&#039;t. But you never know.


2) If the above fails (likely) then the only option i see is to buy a cheap router or put your ADSL modem in router mode (if it can do that). Next you can choose, either give your router a LAN IP inside your current LAN-Trust subnet. In your PBR on trust-vr you then just set next-hop lan-ip-new-router. 
Or create a new private subnet and connect that statically to your ISP2-vr and ISP2 zone set interface. Follow my example above to route traffic out trough the chosen interface.

On both these approaches the router will do NAT and you do not need to do it on the Netscreen for this traffic. In the last approach you will need policies allowing traffic from trust to ISP2, but this last approach will also allow bandwidth shaping, while intra-zone (Trust-Trust) traffic won&#039;t. Another note is that the last approach makes sure users never put the router-lan-ip as std. gateway instead of the Netscreen.

Hope this helps !
Regards Stan</description>
		<content:encoded><![CDATA[<p>Hi yasser,<br />
Luckily for me the ADSL PPoE was static.<br />
Sometimes even with dynamic PPoE connections the gateway always stays the same. If that&#8217;s the case for you, then you can follow my example.</p>
<p>If not, then you have a problem.<br />
1) You could put the interface back in trust-vr and find some way to make your statically set gateway a higher priority. I didn&#8217;t found out how to to do it, and someone on the juniper forum said you just can&#8217;t. But you never know.</p>
<p>2) If the above fails (likely) then the only option i see is to buy a cheap router or put your ADSL modem in router mode (if it can do that). Next you can choose, either give your router a LAN IP inside your current LAN-Trust subnet. In your PBR on trust-vr you then just set next-hop lan-ip-new-router.<br />
Or create a new private subnet and connect that statically to your ISP2-vr and ISP2 zone set interface. Follow my example above to route traffic out trough the chosen interface.</p>
<p>On both these approaches the router will do NAT and you do not need to do it on the Netscreen for this traffic. In the last approach you will need policies allowing traffic from trust to ISP2, but this last approach will also allow bandwidth shaping, while intra-zone (Trust-Trust) traffic won&#8217;t. Another note is that the last approach makes sure users never put the router-lan-ip as std. gateway instead of the Netscreen.</p>
<p>Hope this helps !<br />
Regards Stan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Netscreen policy based routing cross virtual router by Yasser</title>
		<link>http://ares.gobien.be:8080/2010/04/netscreen-pbr-cross-virtual-router/comment-page-1/#comment-9</link>
		<dc:creator>Yasser</dc:creator>
		<pubDate>Mon, 31 May 2010 11:53:52 +0000</pubDate>
		<guid isPermaLink="false">http://ares.gobien.be:8080/?p=89#comment-9</guid>
		<description>Hi Stan,

Thanks for this explanation, i have almost the same situation, but my problem is that the second ISP link is an ADSL PPoE which means you got the IP address from the ISP automatically, in that case i won&#039;t be able to define the IP address of the gateway as i don&#039;t know it and it is been changed every time you reset the line, do you have any idea how can i follow the same steps you added but use the Interface as a gate way instead of the IP?!! 
Thanks.
Best Regards,
Yasser</description>
		<content:encoded><![CDATA[<p>Hi Stan,</p>
<p>Thanks for this explanation, i have almost the same situation, but my problem is that the second ISP link is an ADSL PPoE which means you got the IP address from the ISP automatically, in that case i won&#8217;t be able to define the IP address of the gateway as i don&#8217;t know it and it is been changed every time you reset the line, do you have any idea how can i follow the same steps you added but use the Interface as a gate way instead of the IP?!!<br />
Thanks.<br />
Best Regards,<br />
Yasser</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ares server statistics by Lerenka</title>
		<link>http://ares.gobien.be:8080/ares-server-statistics/comment-page-1/#comment-8</link>
		<dc:creator>Lerenka</dc:creator>
		<pubDate>Mon, 19 Apr 2010 06:28:25 +0000</pubDate>
		<guid isPermaLink="false">http://ares.gobien.be:8080/?page_id=79#comment-8</guid>
		<description>RRDtool is definitely the best monitoring tool ever</description>
		<content:encoded><![CDATA[<p>RRDtool is definitely the best monitoring tool ever</p>
]]></content:encoded>
	</item>
</channel>
</rss>

