[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW1] Routing on firewalls



    [ The following text is in the "iso-8859-2" character set. ]
    [ Your display is set for the "US-ASCII" character set. Some ]
    [ characters may be displayed incorrectly. ]



After instalation is the default policy drop everything. Install policy any any
any accept on the firewall, then is gona work.


                    Petr M





"Haji, Mohmed" <HajiM@logica.com> 05.11.99 16:03:10
Komu:     "'fw-1-mailinglist@lists.us.checkpoint.com'"
      <fw-1-mailinglist@lists.us.checkpoint.com>
Kopie:         (Na vědomí: Petr Menclik/Deltax)
Předmět:      [FW1] Routing on firewalls



    [ Part 2: "Attached Text" ]



I am trying to install a firewall. I have sucessfully installed the licence.
I have not yet installed a security policy or run the fwputkey command.

We have the following configuration

firewall IP1 ----------  IP2 Building Router IP3 ------------- Internal
Network

IP1 = 193.123.204.9
IP2 = 193.123.204.10
IP3 = 158.234.70.1
Internal network = Class B addresses with the Class B address 158.234.0.0

I can ping IP2 from a machine in our internal network. But I can't ping IP1
(the firewall interface). This suggests to me that the routing table on the
building router is OK but the routing table on the firewall isn't.

I think that I need to add a static route to the internal network on the
firewall.
To this end, I used the following command

route add 158.234.0.0/16 193.123.204.10

Where the Subnet Mask is 16 and 193.123.204.10 is IP3 on the diagram above.
(The 158.234.0.0 is the network ID of our internal network as explained
above).

After doing this, I tried pinging the firewall but got the same request
timed out message. When I checked the routing table using the netstat -nr
command, I found that the route I added wasn't listed. Is what I tried to do
correct? What am I doing wrong?

Many thanks for any help offered!


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================