----- Original Message ----- From: "Phil Mayers" <p.may...@imperial.ac.uk>
To: "Wood, Peter (ISS)" <p.w...@lancaster.ac.uk>
Cc: <juniper-nsp@puck.nether.net>
Sent: Friday, May 24, 2013 12:02 PM
Subject: Re: [j-nsp] SRX 3600 dropped packets - how to debug?



At the moment, the SRX is sitting in front of our "personally owned" VRF; this means all our wireless and wired laptops, and RAS VPN address ranges.

If You run any kind peer-to-peer apps (uTorrent, eMule, etc, also includes Skype) then You'll see that outside peers trying to establish LOADS of unsolicited connection to Your inside hosts.
And all of them will be dropped unless You enable full cone NAT.
HTH
Thanks
Alex
_______________________________________________
juniper-nsp mailing list juniper-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/juniper-nsp

Reply via email to