172 IBM Tivoli Remote Control Across Firewalls
8. When you alter any configuration on the firewall, some services require that
you stop and restart those services. Check if you are missing this point for
any of the services or configuration changes you made.
9. Check netstat -rn command output and make sure the routing information
on the firewall is proper. Check netstat -an command output and see that
the required protocol ports are in the proper state (listening/established).
There are various other sniffer and monitoring tools that give the network
status and can be helpful in tracing the problem.
10.Firewall rules are set based on the direction. So, decide on the parent and
child relation among target/Relay/Controller Proxies and set the rules
accordingly. You need an additional set of rules if you want the traffic flow to
be bidirectional (that is, if the initiator can be from both the sides of firewall).
11.It is always recommended that you do not have any other load on the firewall
machine. Also see that your machine satisfies all the hardware and software
requirements for the specific firewall installation and functionality.