All,
This question may be more suited for a solaris newsgroup, but it does involve the firewall, so forgive me if it is off topic. The scenario: Solaris 8, Check Point VPN-1(TM) & FireWall-1(R) NG Feature Pack 3 Build 53945. An office of ours has to internal networks setup to do work for a vendor, 10.3.1.0 and 10.4.1.0. These networks have been in place for a few months and now management wants to add them to the firewall. The routers, 10.3.1.1 and 10.4.1.1, connect to the vendor via a direct T1 and are controlled by the vendor. The vendor does not want to change the ethernet ip's and the admins want to make re-iping the network a last resort. The interfaces on the firewall are as follows: hme0 10.3.1.2/30 or 255.255.255.252 hme1 10.4.1.2/30 qfe0 10.3.1.5/25 or 255.255.255.128 qfe1 10.4.1.5/25 I understand that by setting qfe0 to 128 I only get half the network, but I have also tried making is /24 to use the whole class c network. The routing tables in solaris show the hme interfaces correctly with: 10.3.1.0 10.3.1.2 U 1 2 hme0 but the qfe interfaces show up as (with /25 netmask): 10.0.0.0 10.3.1.5 U 1 0 qfe0 or (with /24 netmask): 10.3.1.0 10.3.1.5 U 1 0 qfe0 So if I bring up both qfe interfaces the firewall freaks out with address-spoofing cause the os can not figure out how to route this stuff correctly. Has anybody been successful at making something like this work? I am really stressing the point that even if it starts working I don't know how reliable it will be. I really want the routers and the internal net to be ip'd differently. Any suggestions are welcomed..... Thanks, Chad ______________________________________________________________________ This email has been scanned by the MessageLabs Email Security System. For more information please visit http://www.messagelabs.com/email ______________________________________________________________________ ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
