Hi, all,

I use FW-1 3.0b(SP 8) on HP-UX 10.2, and I meet a strange problam:

The internal user after FW-1 can use http and ICMP service to access
any external IP address. 

The problam is: for some web site, the user can ping them, but can't 
http them. If I http them before firewall, all is normal.

Then I do bellow test:

1. I telnet the site's port 80, it is active.
2.I use sniffer to capture the package between the firewall and router,
  I find that when use http the sites, there are some information:
  Source       Destination         Summary
 User's IP     Site's IP         ICMP: Destination unreachable(Fragmentation
                                 needed an DF)  
 User's IP     Site;s IP         Retransmission       

Who know why?

Thanks

Tim Lee
----------------------------------------------------------
���۹���Ȥζ����21CN����֮��λ���ܽ��𳬹�100��Ԫ��
�뼴����http://www.21cn.com/21cntoday

21CN(www.21cn.com)֧��CNNIC���飬�뵽http://fsurvey.cnnic.net.cn/survey/index.html
Ͷwww.21cn.comһƱ!


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to