
1.1.8. Multicast Protocol
Symptom Solution
The router does not support IP multicast
forwarding on an IGMP interface without the
multicast routing protocol enabled.
Keep PIM-SM or PIM-DM enabled on the
IGMP interface to insure multicast runs
correctly.
Enabling
ip unnumbered
on a PIM-SM
interface disables PIM-SM routing.
Do not configure
ip unnumbered
on a PIM-SM
interface.
1.1.9. Security
Symptom Solution
ACL match counts are not logged.
ACL match counting is only supported with the
firewall feature.
IPSec in transport mode will transmit transit
traffic with no security headers. IPSec in
transport mode is designed for direct
communications between two peers running
IPSec.
Use Tunnel mode if you are configuring the
router to be an IPSec gateway.
IPSec nesting (i.e. the encrypting of already
encrypted packets) is not supported in this
release.
IPSec nesting is not supported in this release.
The Encryption card status message,
Byte
Order: Not consistent with host
,
can be misleading.
Disregard this status message.
Only one security association is used for each
ACL-incompatible with per-rule implementation.
Create one separate ACL for each permit
statement in the third-party access list.
To telnet or SSH to a 3Com Router there must
be a local user defined on that 3Com router.
Configure a local-user on the router for telnet
or SSH access
Routers that are defined within a Server ACL
on the Master Clock router will not sync to the
Master
From the Master Clock router, define each
router as a Peer of the clock source router
within a Peer ACL if these routers are to be
synchronized by the Master.
In addition, direct NTP messages to the master
using the unicast server command on the
routers.
The encryption card in combination with some
features may cause ping responses or traffic to
be slowed. Example: Encryption card with
GRE, MP, IPSec.
If problems occur with securely managing or
pinging the router via an IPSec tunnel, use a
software encryption policy instead of an
encryption card policy.
It is difficult to exit from the SSH public key
configuration without a valid key
Enter another view, such as interface view,
using the command
interface Ethernet 0
, then
quit.
3Com Router Release Notes for V1.20
8