If you have a SonicWALL hardware firewall there are two methods you can use to setup your system to respond to pings:
Method 1: You can pass incoming pings through the SonicWALL to a PC on the LAN and then have the PC respond to the pings.
Method 2: You can have the SonicWALL respond to pings directly.
To use Method 1 (your PC responds to pings) follow these steps:
(1a) Open the SonicWALL web admin by entering the SonicWALL's LAN IP address into a web browser on a PC on the LAN side of the SonicWALL.
(1b) Go to Access, Services and make sure Ping shows up in the list of services. If not, add the Ping service.
(1c) Go to Access, Rules, Add New Rule and add two rules Rule 1 - Action=allow - Service=ping - Source=WAN, 216.200.176.6 <= DSLR WC server “sjc-monitor.dslreports.com” - Destination=LAN, 192.x.x.x <= LAN address of PC to respond to pings Rule 2 - Action=allow - Service=ping - Source=WAN, 206.65.191.129 <= DSLR EC server “ny-monitor.dslreports.com” - Destination=LAN, 192.x.x.x <= LAN address of PC to respond to pings
(1d) If you have a software firewall on the LAN PC be sure to allow pings there as well.
To use Method 2 (SonicWALL responds to pings) follow these steps: (2a) Open the SonicWALL web admin by entering the SonicWALL's LAN IP address into a web browser on a PC on the LAN side of the SonicWALL.
(2b) Go to Access, Services and make sure Ping shows up in the list of services. If not, add the Ping service.
(2c) Go to Access, Rules, Add New Rule and add two rules Rule 1 - Action=allow - Service=ping - Source=WAN, 216.200.176.6 <= DSLR WC server “sjc-monitor.dslreports.com” - Destination=LAN, 192.x.x.x <= LAN address of SonicWALL Rule 2 - Action=allow - Service=ping - Source=WAN, 206.65.191.129 <= DSLR EC server “ny-monitor.dslreports.com” - Destination=LAN, 192.x.x.x <= LAN address of SonicWALL
General notes:
You can have the SonicWALL “stealth mode” enabled (Access, Services, Stealth Mode) and both methods will still work.
You can use “*” for the WAN address in the SonicWALL rules to allow pings from anyone, but the nice thing about using explicit rules for each DSLR server is that you don't make yourself visible to the general public. I don't think it's a security risk to leave the server-specific rules in place. Of course, if DSLR changes their server IP addresses you need to change your rules.
show feedback form
close
by wingman8 edited by KeysCapt  last modified: 2002-07-23 14:07:27 |