I was able to setup a SecureRemote in Win2k which connects to Linux running
FW-1. I setup an isolated lab wherein the external interface of linux uses a
public ip address and private ip on the internal interface. I erased
everything including the IP addresses of my cisco. And instead, I used
private ip address for all the configuration. I tested SecureRemote and
couldn't connect anymore. Should this be normal?

Btw, I'm using EVAL licenses.

Another issue. With the first setup which uses public and private ip
address, I am unable to connect to my webserver behind the linux firewall.
The ip address of the webserver is at 192.168.10.10.

Firewall External = 200.1.1.2
Firewall Internal = 192.168.10.1

I picked an IP address which I will use for the destination static, and that
is 200.1.1.10. So what I did was
a. fwstop
b. arp -a 200.1.1.10 MAC-ADDR-OF-EXTERNAL-INTERFACE pub
c. route add -host 200.1.1.10 gw 192.168.10.10
d. fwstart

I also added a rule:

Any   webserver   http

I tried reaching 200.1.1.10, but I couldn't get the webpage.

So what I did, I erased everything again. Replaced public ip address with
private. And redid what I wrote above then tested. I was able to connect to
the webserver.

Any ideas why this happens? Or this should be normal so that no one can just
use EVAL licenses for production/live setups.

Thanks.

Neil
_______________________________________________
Firewalls mailing list
[EMAIL PROTECTED]
http://lists.gnac.net/mailman/listinfo/firewalls

Reply via email to