> 1)The arp entry is like this
>   206.234.243.134 <MAC address of FW's external interface>
Well that is correct. And this is in local.arp?

> 3)I am able to ping my router now 206.234.243.1 and host also 172.16.1.134
> but only after checking the option Policy>Properties>
>   Security Policy>Accept ICMP(before last)
You should enable a specific rule in your firewall policy instead of
allowing ICMP through the implied policy.

> 4)I am able to reach my FW's external IP from tracert.com but not able to
> reach my NAT IP 206.234.243.134 from the net(in this case i fail to each my
> FW's external IP also!!)
Traceroute is a funny protocol and is not the best for troubleshooting.
You may wish to test connectivity with an application such as telnet or
http.

-Don

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to