[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] RE: [FW1] VRRP and NAT
For static NAT in a VRRP environment (which I believe you are talking about), we did the following: 1) Instead of using proxy arp, we created a "backup" VRRP address. According to some doc I recently read, this is the preferred method. 2) Create a static route to marry the addresses together i.e. outside backup vrrp address ------ real host address 3) Create the appropriate rule in the rulebase and the address translation rule. For HIDE NAT in a VRRP environment, we did the following: 1) See above 2) Create the approriate rule in the address translation table using the created VRRP backup address to hide behind. Regards................Elliot "Thomas Stala" <[email protected]>@lists.us.checkpoint.com on 02/11/2001 11:21:50 PM Please respond to <[email protected]> Sent by: [email protected] To: "Chris Arnold" <[email protected]>, <[email protected]> cc: Subject: RE: [FW1] VRRP and NAT Well when I setup the hide I used the real IP of the external interface. I was told that using static routing with VRRP you should use proxy for the ARP and the VRRP MAC address. Please if this is not correct someone please correct me. ;-} I am new to the Nokia world Thomas Stala [email protected] Hope this helps -----Original Message----- From: [email protected] [mailto:[email protected]]On Behalf Of Chris Arnold Sent: Tuesday, January 09, 2001 4:46 PM To: [email protected] Subject: [FW1] VRRP and NAT Uh oh, doesn't look like I can do hide behind NAT on my VRRP (MC) virtual address for my external interfaces. PLEASE correct me if I'm wrong. Chris ============================================================================ ==== To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ============================================================================ ==== ================================================================================ To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================================================ ================================================================================ To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================================================
|