CLEANACCESS Archives

November 2005

CLEANACCESS@LISTSERV.MIAMIOH.EDU

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Cal Frye <[log in to unmask]>
Reply To:
Perfigo SecureSmart and CleanMachines Discussion List <[log in to unmask]>
Date:
Tue, 8 Nov 2005 15:24:48 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (71 lines)
Alex, Todd, many thanks -- Rule 1 sounds exactly like what we're seeing. We'll
see if that fixes it.

--Cal Frye, Network Administrator, Oberlin College
   www.ouuf.org, www.calfrye.com
   Say Yes Twice for Oberlin Schools!   www.oberlinyesyes.com

  "A clever man commits no minor blunders." - Goethe (1749-1832)


Alex Tirdil wrote:
> Hello Cal,
> 
> I was using 7.0.1g1 with the XboxLive classification and was getting
> the same complaints from my users.  I kept that service in there, but
> added 2 extra rules:
> 
> Rule1:
> Device = Any
> Protocol = IP
> Ports (outside) = 3074
> 
> Rule2:
> Device = Any
> Protocol = IP
> Ports (Inside) = 1257 | Ports (Outside) = 88
> 
> Pretty sure Rule1 is some authentication server, as no one could even
> login to xbox live until i added that Rule1.  Not sure what Rule2 is, it
> might have been for a specific game.  Regardless, all my xbox gamers say
> it works well except during peak hours.  We have about 3000 resnet
> students and inbound for games (including xboxlive) is 1MB burstable to
> 3MB.  Outbound is 400k burstable to 2MB.
> 
> ______________________
> Alex Tirdil
> Network Control Specialist
> Salisbury University
> [log in to unmask]
> ~~~~~~~~~~~~~~~~~
> 
> 
>>>>Cal Frye <[log in to unmask]> 11/8/2005 12:50 PM >>>
> 
> Hi, all,
> Can someone with XBox experience help me out? My XBox users are pretty
> angry
> with me by now. They complain they still cannot connect to XBox
> Live...
> 
> I have:
> On the Packetshaper, a ResNet gaming partition of 0-3MB. Within that
> are
> multiple game classes, including one for XBoxLive (standard defn for
> 7.0.1g1).
> 
> My Perfigo/CCA gateways have a user role for gaming systems that
> permits DNS,
> NTP, and all off-campus traffic as well as within-dorm traffic. We
> manually
> enter the MAC address of XBoxes and Playstations into this role.
> 
> It would seem I can hardly open up the traffic classes any more for
> this gear.
> The final question might be with our firewall, but that configuration
> is pretty
> minimal. Short of NetBIOS in general, and specific attack signatures,
> we let
> nearly all else through. What does XBox need to connect to Live?
> 

ATOM RSS1 RSS2