A glass of your favorite brew if anyone can help me from pulling my hair
further out. I'm really at wit's end.

Nokia IP650, FW-1 v4.1 SP6, etc.

Inside interface (10.1.1.1)
External interface (12.149.150.1)
DMZ interface (12.149.150.128)
DMZ server (12.149.150.130)

Rules:

any fw1 http accept
[EMAIL PROTECTED] dmz_server http client_auth
any any drop

Using FW1 passwords for testing, if I have it set to User Auth, it works
every which way to reach the DMZ server.  Outside people get in, inside
people get in to the DMZ server, perfect.

I switch to Client Auth so I can open up an IP instead of just that
session, and it only works from the inside.

>From the outside I try to connect and it sits and sits, and when I "stop"
the browser, I get a line that looks like (sorry, from memory):

10.1.1.1/fwauthredirect/12.149.150.1

...it looks like request from the outside are getting redirected to the
inside interface of the firewall, which of course gets lost.  It is like
the "default" interface for FW-1 somehow is my internal interface, rather
than the external one.

I've been around FW-1 for a while and think I know my way around fairly
well, but I'm really pulling my hair out over this.

I've use FW-1 on NT for quite a while and the redirect line is correct --
external interface redirecting to the proper server.

I've enabled http access to the FW, changed the HTTP server on the Nokia
from 80 to 8080 just to be safe, etc.

HELP!  I'm going completely nuts over this.  I scoured Google for a good
part of today and found a few people with the same problem, but no
solutions.

Anyone?  Anyone?  A cold glass of your favorite if you can help!

--Doug Mason, San Francisco, CA

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to