On NT:

example:
the fw-1 ext interface:                         207.43.192.6
the ext interface you want to proxy:    207.43.192.5
the int interface of the proxied:               10.10.0.33
MAC address of the proxied:                     00-80-5e-f7-e2-a2

add route to firewall:

route -p add 207.43.192.5 MASK 255.255.255.255 10.10.0.33

edit file %fw%\state\local.arp and add line:

207.43.192.5 00-80-5e-f7-e2-a2

if this doesn't work (with fw-1 on NT often it doesn't) phoneboy
www.phoneboy.com has more information about proxy arp from a router.  the
command in cisco IOS is something like:

     ext_ip             MAC
arp w.x.y.z 0000.abcd.1234 arpa

research it before using it, I don't remember which mac you use (the fw or
what...)

I hope this helps more that 'get a real machine'....

> -----Original Message-----
> From: Imran Ali [mailto:[EMAIL PROTECTED]]
> Sent: Wednesday, July 12, 2000 2:21 PM
> To: [EMAIL PROTECTED]
> Subject: [FW1] How to setup ftp and htttp w/ FW-1 External Interface
> Only
> 
> 
> 
> Does anybody knows how to redirect ftp and www  to internal 
> servers with
> only fw-1 external (valid ip) address. I also have interal users that
> need access to http,ftp, and telnet. I have done NAT with 
> internal users
> going out via a NAT hiding translating rule and ftp and www are done
> with static rules. I also have appropriate access rules in fw-1. I can
> see packets entering the fw in the logs but it seems like they are not
> routed (or getting out of the fw).
> 
> Thanks in advance
> -Imran Ali
> 
> 
> 
> ==============================================================
> ==============
> ====
>      To unsubscribe from this mailing list, please see the 
> instructions at
>                http://www.checkpoint.com/services/mailing.html
> ==============================================================
> ==============
> ====
> 
> 
> ==============================================================
> ==================
>      To unsubscribe from this mailing list, please see the 
> instructions at
>                http://www.checkpoint.com/services/mailing.html
> ==============================================================
> ==================
> 


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to