locked
Configuration error - MPLS RRS feed

  • Question

  • Hi,

    I received this event after TMG 2010 startup: The network "MPLS" does not correlate with the network adapters that belong to it.
    Ranges in adapter "MPLS" that do not belong to network "MPLS": 192.168.2.0-192.168.4.255,192.168.7.0-192.168.11.255,192.168.101.0-192.168.101.249,192.168.101.251-192.168.101.255;
    When networks are configured correctly, the IP address ranges included in each array-level network must include all IP addresses that are routable through its network adapters according to their routing tables. Otherwise valid packets may be dropped as spoofed. 

    I have MPLS network (from ISP - Cisco router) which are connected to one NIC on TMG. In this NIC I configured only IP: 192.168.101.250/24 (no DGW, DNS and so on).

    MPLS have these subnets: 192.168.2.0/24, 192.168.3.0/24, 192.168.4.0/24, 192.168.7.0/24, 192.168.8.0/24, 192.168.9.0/24, 192.168.10.0/24, 192.168.11.0/24, 192.168.101.0/24

    In Routing and Remote Access I configured all MPLS subnets. 

    In TMG console I configured Networks - Addres Ranges and create new Network Rules which defined route to internal network. After that everything is working but I still receive "Configuration error" in monitoring and sometimes TMG evaluate IP or Packet spoofing from MPLS subnets.

    Monday, April 16, 2012 7:56 AM

Answers

  • Hi,

    Thank you for the post.

    The Address Range in the config should be the full range and all the ranges that are directly reachable via that internal Nic.

    Regards,


    Nick Gu - MSFT

    Monday, April 23, 2012 1:51 AM
    Moderator

All replies

  • No one?
    Thursday, April 19, 2012 7:15 AM
  • Hi,

    Thank you for the post.

    The Address Range in the config should be the full range and all the ranges that are directly reachable via that internal Nic.

    Regards,


    Nick Gu - MSFT

    Monday, April 23, 2012 1:51 AM
    Moderator