Hi,

Why you plug the ISDN-WAN not between the Firewall and the Frame Router?!

> We're running NG FP3 on a Win2K SP3 box. We are using this box as the
> firewall & the default gateway for the nework. Everything is working
> perfectly for the majority of traffic, both WAN & Internet, that is
> supposed
> to flow through the firewall, but we have a problem getting the firewall
> to
> redirect packets to another router (see diagram).

>                 Firewall     Frame Router
>                    __           __
> Network ----------|__|---------|__|-------Internet & WAN traffic via
> single
> frame link
> 10.x.x.x/22   |  10.x.x.254
>               |
>               |      ISDN Router
>               |          __
>                ---------|__|------------------ISDN
>                       10.x.x.81

> The reason for the ISDN & frame links is that the ISDN is for local sites
> &
> therefore significantly less expensive (approx 1/3 the cost) than using
> the
> frame link.

> The plan is for all traffic to be routed to the firewall at 10.x.x.254 &
> for
> it to reroute packets (using either a static route or preferably RIP) for
> networks on the ISDN WAN to the ISDN router.

> This works for traffic initiated inside the network going to the ISDN WAN
> as
> it goes from the network host to 10.x.x.254 which sends it to 10.x.x.81.
> When the response comes back in it goes from 10.x.x.81 directly to the
> network host, obviously bypassing the firewall at 10.x.x.254.

> However, when traffic is initiated from the ISDN WAN end it goes from
> 10.x.x.81 directly to the host. The response from the host goes to
> 10.x.x.254 (ie the firewall) which drops the packets as being out-of-state
> (probably because the firewall see a response to a request that didn't
> come
> via it).

> Am I correct in assuming that NG inspects the packets before doing any
> routing? Is there any way to get NG to process the routing BEFORE the
> inspection?

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to