-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 sin wrote: > Thorsten Mandau wrote: >> Hi, >> >> < We noted that NAT rules were never matched. Then we found that groups >> < and ranges get expanded for NAT rules. >> >> I don't want to use these ip range objects in our NAT rules. We just >> need them in our security rulebase. So, would there any problems using >> them in the security rulebase? Otherwise we have to create more than >> 6000 node objects... > > From what Hugo says, you can use address ranges as it will be expanded > to individual IPs, so basically you get an automated way of declaring > 6000 objects ;) kinky, no ? :))
No. You get the ranges. Wether or not the resulting policy will expand all of it in binary form is something I have not tested. But I would expect that at some point during compilation they are in act expanded. So the only way to know this is to test it. Hugo. - -- [EMAIL PROTECTED] http://hugo.vanderkooij.org/ PGP/GPG? Use: http://hugo.vanderkooij.org/0x58F19981.asc Bored? Click on http://spamornot.org/ and rate those images. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) iD8DBQFHF71KBvzDRVjxmYERAhYqAJ9xGAnHkMkj0KRzR6tvaSZ0hAEUsQCgkeCP zkEiS10J2jSnv3ZlvgOKZp4= =3I+T -----END PGP SIGNATURE----- ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
