NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW1] Re: More than 1 external subnets techniques



Good $daytime,

> Date: Thu, 8 Feb 2001 22:44:52 +0200
> From: Mario Kadastik <[email protected]>
> To: [email protected]
> Subject: [FW1] More than 1 external subnets techniques 

> a) When adding an iface hme0:1 with the new subnet, it won't be
> pingable ...

Don't you forget to bring it UP?  In some other unices, 
`ifconfig <iface> <addr>` implies `ifconfig <iface> <addr> up`.  

> b) When adding just one IP on hme0:1 it's pingable, but there might
> be a licensing issue...  because fw might just count ip-s from there
> as internal (has happened)

Ei ole, if you look at `strconf < hme0`, you'll see 'fw' module well
below 'ip'.  This means that IP aliases are effectively
indistinguishable at that level.

What you may have forgotten is to fix your firewall object definition
to reflect the change.  Without that, rule that allows you pinging
your firewall won't work.

> So everyone out there having a clue, how to do multiple subnets on
> one ext. if and smth that would work, would be nice to hear from you

I am working with IP aliases in my external interfaces, even with
different netmasks.  Nothing wrong to date...

  Regards,
  Willy.

--
"No easy hope or lies        | Vitaly "Willy the Pooh" Fedrushkov
 Shall bring us to our goal, | Control Systems and Processes Division
 But iron sacrifice          | LUKOIL Company, Chelyabinsk Branch
 Of Body, Will and Soul."    | mailto:[email protected]  +7 3512 620367
                   R.Kipling |



================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.