Hi, Why you plug the ISDN-WAN not between the Firewall and the Frame Router?!
> We're running NG FP3 on a Win2K SP3 box. We are using this box as the > firewall & the default gateway for the nework. Everything is working > perfectly for the majority of traffic, both WAN & Internet, that is > supposed > to flow through the firewall, but we have a problem getting the firewall > to > redirect packets to another router (see diagram). > Firewall Frame Router > __ __ > Network ----------|__|---------|__|-------Internet & WAN traffic via > single > frame link > 10.x.x.x/22 | 10.x.x.254 > | > | ISDN Router > | __ > ---------|__|------------------ISDN > 10.x.x.81 > The reason for the ISDN & frame links is that the ISDN is for local sites > & > therefore significantly less expensive (approx 1/3 the cost) than using > the > frame link. > The plan is for all traffic to be routed to the firewall at 10.x.x.254 & > for > it to reroute packets (using either a static route or preferably RIP) for > networks on the ISDN WAN to the ISDN router. > This works for traffic initiated inside the network going to the ISDN WAN > as > it goes from the network host to 10.x.x.254 which sends it to 10.x.x.81. > When the response comes back in it goes from 10.x.x.81 directly to the > network host, obviously bypassing the firewall at 10.x.x.254. > However, when traffic is initiated from the ISDN WAN end it goes from > 10.x.x.81 directly to the host. The response from the host goes to > 10.x.x.254 (ie the firewall) which drops the packets as being out-of-state > (probably because the firewall see a response to a request that didn't > come > via it). > Am I correct in assuming that NG inspects the packets before doing any > routing? Is there any way to get NG to process the routing BEFORE the > inspection? ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
