NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW1] anti-spoofing on aliased interfaces



Lance,

I think they can be used, but fw1 will not report
stats on them, only the physical. They cannot
be licensed.

Per Phoneboy:

FireWall-1 versions prior to 2.1 supported 8 physical interfaces and 32 total interfaces (real + virtual). Versions 2.1-3.0b support 32 physical interfaces and 255 total (real + virtual). Obviously, there are some physical limitations as well. Version 4.0 was supposed to support an unlimited number of physical interfaces, but it appears to be limited to 64 real interfaces. Because of how IPSO treats virtual interfaces, the "real" limits are also apply to virtual IPs as well, including VRRP addresses. 

Robert

- -
Robert P. MacDonald, Network Engineer
e-Business Infrastructure
G o r d o n   F o o d    S e r v i c e
Voice:email: [email protected]

>>> Lance Spitzner <[email protected]> 9/29/00 2:33:53 PM >>>
>
>I've aliased an interface (hme0:1) on FW ver 4.1, running on Solaris.
>
>Can one add an aliased interface to the interface objects
>on a firewall?
>
>Can one setup anti-spoofing on an aliased interface?
>
>Last, does the aliased interface show up on the 'fw stat -li'
>command?
>
>Thanks!
>
>-- 
>Lance Spitzner
>http://www.enteract.com/~lspitz 




================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents � 2003 Network Presence, LLC. All rights reserved.