nv-l
[Top] [All Lists]

Re: NetView & MLM in firewall scenario

To: nv-l@lists.tivoli.com
Subject: Re: NetView & MLM in firewall scenario
From: "Sarah Romeis" <sromeis@us.ibm.com>
Date: Mon, 12 Mar 2001 11:09:31 -0500
Don,
Hello. I am interested in the tavve ePROBE solution... Did you go with that
to be able manage multiple private addressed customers from one Netview
without having to set up all the CNATs? Just interested in why you had
ePROBE in the first place... THanks

Sarah  Romeis
Network Management/Application Support
IBM Global Services 1630 Long Pond Rd Rochester, NY 14626
Internet: sromeis@us.ibm.com
Lotus Notes: IBMUSM10(SROMEIS)
Voice: (716) 723-4354  Fax:(716) 723-4299

   "A team exists only when a player understands how his actions affect
others."   - Vince Lombardi



"Don Sykes" <Don.Sykes@bcbsnc.com>@tkg.com on 03/12/2001 09:51:11 AM

Please respond to IBM NetView Discussion <nv-l@tkg.com>

Sent by:  owner-nv-l@tkg.com


To:   <jane.curry@skills-1st.co.uk>, <nv-l@tkg.com>
cc:
Subject:  Re: [NV-L] NetView & MLM in firewall scenario



This is exactly what we tried to do in our environment but were
unsuccessful in making it work.  We finally determined that MLM was not
designed to do discovery.  Since we already have a Tavve installation, we
decided to go with their eProbe solution.  We'll be implementing this over
the next couple of weeks.  I'll post the results if anyone's interested....


Don Sykes
Blue Cross and Blue Shield of North Carolina
Innovative health care designed around you!


>>> Jane Curry <jane.curry@skills-1st.co.uk> 03/11/01 08:57AM >>>
Has anyone tried the following????  I want to use an MLM to do discovery
and status polling beyond a packet-filtering firewall.

    NetView ------>  Firewall ------> MLM -------> Managed Devices

The firewall ONLY permits UDP/162  NetView <-> MLM, and UDP/161 NetView
<-> MLM;  there is no SNMP/161 or ping allowed to the managed devices.
I also have UDP/162 (traps) from the Managed Devices to MLM and/or
NetView.

At this stage, I don't have ping to the MLM either but I can tell netmon
to poll the MLM using SNMP in the seedfile.  I have no firewall between
MLM and the managed devices so ping and SNMP traffic is fine.

If I tell netmon to use MLM for both discovery and polling, I should
have full comms to the MLM - no problem.  I hope that the MLM will then
discover the Managed Devices, pass them back to NetView, and also add
them to his MLM status polling table.  WILL THIS WORK?????  - even
though NetView himself cannot ping or demand poll the devices?  I want
the Managed Devices to appear in the NetView topology as managed by the
MLM.  I don't care if NetView thinks they don't support SNMP, so long as
the box is there and it goes red/green depending on the Node Up/Down
traps passed from the MLM.

I would much appreciate any feedback from anyone who has been down this
route.
Kind regards,
Jane
--
Tivoli Certified Enterprise Consultant & Instructor
Skills 1st Limited, 2 Cedar Chase, Taplow, Bucks, SL6 0EU, UK
Tel: +44 (0)1628 782565
Copyright (c) 2001 Jane Curry <jane.curry@skills-1st.co.uk>.  All rights
reserved.


_________________________________________________________________________
NV-L List information and Archives: http://www.tkg.com/nv-l

_________________________________________________________________________
NV-L List information and Archives: http://www.tkg.com/nv-l


<Prev in Thread] Current Thread [Next in Thread>

Archive operated by Skills 1st Ltd

See also: The NetView Web