Alex, Todd, many thanks -- Rule 1 sounds exactly like what we're seeing. We'll
see if that fixes it.
--Cal Frye, Network Administrator, Oberlin College
www.ouuf.org, www.calfrye.com
Say Yes Twice for Oberlin Schools! www.oberlinyesyes.com
"A clever man commits no minor blunders." - Goethe (1749-1832)
Alex Tirdil wrote:
> Hello Cal,
>
> I was using 7.0.1g1 with the XboxLive classification and was getting
> the same complaints from my users. I kept that service in there, but
> added 2 extra rules:
>
> Rule1:
> Device = Any
> Protocol = IP
> Ports (outside) = 3074
>
> Rule2:
> Device = Any
> Protocol = IP
> Ports (Inside) = 1257 | Ports (Outside) = 88
>
> Pretty sure Rule1 is some authentication server, as no one could even
> login to xbox live until i added that Rule1. Not sure what Rule2 is, it
> might have been for a specific game. Regardless, all my xbox gamers say
> it works well except during peak hours. We have about 3000 resnet
> students and inbound for games (including xboxlive) is 1MB burstable to
> 3MB. Outbound is 400k burstable to 2MB.
>
> ______________________
> Alex Tirdil
> Network Control Specialist
> Salisbury University
> [log in to unmask]
> ~~~~~~~~~~~~~~~~~
>
>
>>>>Cal Frye <[log in to unmask]> 11/8/2005 12:50 PM >>>
>
> Hi, all,
> Can someone with XBox experience help me out? My XBox users are pretty
> angry
> with me by now. They complain they still cannot connect to XBox
> Live...
>
> I have:
> On the Packetshaper, a ResNet gaming partition of 0-3MB. Within that
> are
> multiple game classes, including one for XBoxLive (standard defn for
> 7.0.1g1).
>
> My Perfigo/CCA gateways have a user role for gaming systems that
> permits DNS,
> NTP, and all off-campus traffic as well as within-dorm traffic. We
> manually
> enter the MAC address of XBoxes and Playstations into this role.
>
> It would seem I can hardly open up the traffic classes any more for
> this gear.
> The final question might be with our firewall, but that configuration
> is pretty
> minimal. Short of NetBIOS in general, and specific attack signatures,
> we let
> nearly all else through. What does XBox need to connect to Live?
>
|