[AG-TECH] Firewall & AG

John Hofmann hofmannj at cookman.edu
Tue Aug 24 15:50:43 CDT 2004


We use a GRE tunnel THROUGH our firewall and static NAT on our core
switch/router.

-----Original Message-----
From: owner-ag-tech at mcs.anl.gov [mailto:owner-ag-tech at mcs.anl.gov] On
Behalf Of Fred Dech
Sent: Tuesday, August 24, 2004 3:00 PM
To: AG_Tech_List
Subject: [AG-TECH] Firewall & AG

hi.

i know this has been asked before, but i never saw any detailed replies.

lots of you out there have very tight firewalls, but still run AG
effectively
with multicasting.

we have a collaborator who is tentative about multicasting to begin
with,
and is very keen on only opening port addresses that are absolutely
necessary
for MCAST and AG sessions to work.  they may even just open them for the
scheduled sessions and then close them up again for all i know.  i'm not
that
savvy when it comes to the firewall / usable mcast AG trade-off.  the
site
in question will be running AG from a single Windows box.

can someone send out a brief description of the minimum ports/port
ranges
that are required, or point me to some documentation on this issue.

thanks.

--fred




More information about the ag-tech mailing list