Chad,
You could change the system to be something as follows but this would mean
that your internal workstations ip addressing would need to change to be
within the Int1-10.3.1.128-NET and Int1-10.4.1.128-NET ranges or you get
the Router interfaces changed...<grin>
Firewall
hme0 10.3.1.2/30 or 255.255.255.252
hme1 10.4.1.2/30
qfe0 10.3.1.129/25 or 255.255.255.128
qfe1 10.4.1.129/25
/etc/networks
Vnd1-10.3.1.0-NET 10.3.1.0 # Vendor1 10.3.1.0/30 network
Vnd2-10.4.1.0-NET 10.4.1.0 # Vendor2 10.4.1.0/30 network
Int1-10.3.1.128-NET 10.3.1.128 # Internal1 10.3.1.128/25 network
Int2-10.4.1.128-NET 10.4.1.128 # Internal2 10.4.1.128/25 network
/etc/netmasks
10.3.1.0 255.255.255.252 # Vnd1-10.3.1.0-NET
10.4.1.0 255.255.255.252 # Vnd2-10.4.1.0-NET
10.3.1.128 255.255.255.128 # Int1-10.3.1.128-NET
10.4.1.128 255.255.255.128 # Int2-10.4.1.128-NET
Regards,
Ken Welsh
"Graham, Chad"
<[EMAIL PROTECTED]
ES.COM> To
Sent by: Mailing [EMAIL PROTECTED]
list for INT.COM
discussion of cc
Firewall-1
<FW-1-MAILINGLIST Subject
@AMADEUS.US.CHECK [FW-1] Interfaces on the same
POINT.COM> network
13/05/2004 06:51
Please respond to
Mailing list for
discussion of
Firewall-1
<FW-1-MAILINGLIST
@AMADEUS.US.CHECK
POINT.COM>
All,
This question may be more suited for a solaris newsgroup, but it does
involve the firewall, so forgive me if it is off topic. The scenario:
Solaris 8, Check Point VPN-1(TM) & FireWall-1(R) NG Feature Pack 3 Build
53945.
An office of ours has to internal networks setup to do work for a
vendor,
10.3.1.0 and 10.4.1.0. These networks have been in place for a few
months
and now management wants to add them to the firewall. The routers,
10.3.1.1
and 10.4.1.1, connect to the vendor via a direct T1 and are controlled
by
the vendor. The vendor does not want to change the ethernet ip's and the
admins want to make re-iping the network a last resort. The interfaces
on
the firewall are as follows:
hme0 10.3.1.2/30 or 255.255.255.252
hme1 10.4.1.2/30
qfe0 10.3.1.5/25 or 255.255.255.128
qfe1 10.4.1.5/25
I understand that by setting qfe0 to 128 I only get half the network,
but I
have also tried making is /24 to use the whole class c network. The
routing
tables in solaris show the hme interfaces correctly with:
10.3.1.0 10.3.1.2 U 1 2 hme0
but the qfe interfaces show up as (with /25 netmask):
10.0.0.0 10.3.1.5 U 1 0 qfe0
or (with /24 netmask):
10.3.1.0 10.3.1.5 U 1 0 qfe0
So if I bring up both qfe interfaces the firewall freaks out with
address-spoofing
cause the os can not figure out how to route this stuff correctly. Has
anybody
been successful at making something like this work? I am really
stressing the
point that even if it starts working I don't know how reliable it will
be. I really
want the routers and the internal net to be ip'd differently. Any
suggestions
are welcomed.....
Thanks,
Chad
______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email
______________________________________________________________________
WARNING - This email and any attachments may be confidential. If received in error,
please delete and inform us by return email.
Because emails and attachments may be interfered with, may contain computer viruses or
other defects and may not be successfully replicated on other systems,
you must be cautious. Westpac cannot guarantee that what you receive is what we sent.
If you have any doubts about the authenticity of an email by Westpac,
please contact us immediately.
It is also important to check for viruses and defects before opening or using
attachments. Westpac's liability is limited to resupplying any affected attachments.
Westpac Banking Corporation ABN is 33 007 457 141.
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================