Chad,

You could change the system to be something as follows but this would mean
that your internal workstations ip addressing would need to change to be
within the Int1-10.3.1.128-NET and Int1-10.4.1.128-NET ranges or you get
the Router interfaces changed...<grin>

Firewall
hme0  10.3.1.2/30 or 255.255.255.252
hme1  10.4.1.2/30
qfe0  10.3.1.129/25 or 255.255.255.128
qfe1  10.4.1.129/25

/etc/networks
Vnd1-10.3.1.0-NET 10.3.1.0    # Vendor1 10.3.1.0/30 network
Vnd2-10.4.1.0-NET 10.4.1.0    # Vendor2 10.4.1.0/30 network
Int1-10.3.1.128-NET     10.3.1.128  # Internal1 10.3.1.128/25 network
Int2-10.4.1.128-NET     10.4.1.128  # Internal2 10.4.1.128/25 network

/etc/netmasks
10.3.1.0    255.255.255.252   # Vnd1-10.3.1.0-NET
10.4.1.0    255.255.255.252   # Vnd2-10.4.1.0-NET
10.3.1.128  255.255.255.128   # Int1-10.3.1.128-NET
10.4.1.128  255.255.255.128   # Int2-10.4.1.128-NET

Regards,

Ken Welsh





             "Graham, Chad"
             <[EMAIL PROTECTED]
             ES.COM>                                                    To
             Sent by: Mailing          [EMAIL PROTECTED]
             list for                  INT.COM
             discussion of                                              cc
             Firewall-1
             <FW-1-MAILINGLIST                                     Subject
             @AMADEUS.US.CHECK         [FW-1] Interfaces on the same
             POINT.COM>                network


             13/05/2004 06:51


             Please respond to
             Mailing list for
               discussion of
                Firewall-1
             <FW-1-MAILINGLIST
             @AMADEUS.US.CHECK
                POINT.COM>






All,



This question may be more suited for a solaris newsgroup, but it does

involve the firewall, so forgive me if it is off topic. The scenario:

Solaris 8, Check Point VPN-1(TM) & FireWall-1(R) NG Feature Pack 3 Build
53945.

An office of ours has to internal networks setup to do work for a
vendor,

10.3.1.0 and 10.4.1.0. These networks have been in place for a few
months

and now management wants to add them to the firewall. The routers,
10.3.1.1

and 10.4.1.1, connect to the vendor via a direct T1 and are controlled
by

the vendor. The vendor does not want to change the ethernet ip's and the

admins want to make re-iping the network a last resort. The interfaces
on

the firewall are as follows:



hme0    10.3.1.2/30 or 255.255.255.252

hme1    10.4.1.2/30

qfe0     10.3.1.5/25 or 255.255.255.128

qfe1     10.4.1.5/25



I understand that by setting qfe0 to 128 I only get half the network,
but I

have also tried making is /24 to use the whole class c network. The
routing

tables in solaris show the hme interfaces correctly with:



10.3.1.0             10.3.1.2              U        1      2  hme0



but the qfe interfaces show up as (with /25 netmask):



10.0.0.0             10.3.1.5              U        1      0  qfe0



or (with /24 netmask):



10.3.1.0             10.3.1.5              U        1      0  qfe0





So if I bring up both qfe interfaces the firewall freaks out with
address-spoofing

cause the os can not figure out how to route this stuff correctly. Has
anybody

been successful at making something like this work? I am really
stressing the

point that even if it starts working I don't know how reliable it will
be. I really

want the routers and the internal net to be ip'd differently. Any
suggestions

are welcomed.....



Thanks,

Chad


______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email
______________________________________________________________________



WARNING - This email and any attachments may be confidential. If received in error, 
please delete and inform us by return email.

Because emails and attachments may be interfered with, may contain computer viruses or 
other defects and may not be successfully replicated on other systems,
you must be cautious. Westpac cannot guarantee that what you receive is what we sent. 
If you have any doubts about the authenticity of an email by Westpac,
please contact us immediately.

It is also important to check for viruses and defects before opening or using 
attachments. Westpac's liability is limited to resupplying any affected attachments.

Westpac Banking Corporation ABN is 33 007 457 141.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to