NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW1] Problem with Management Station



Hi,

We are using a Firewall-1 Clusters with 2 machines Solaris 2.6 and we have a
separate mgmt station on an NT box.

Because we are implementing a new Internet connection I had to break the
cluster up and reconfigure one of the machines to work with the new set of
IP addresses.
Because we have had issues with our "internal" address range, I don't want
the fw to know any routes back in. I have legal addresses for both internal
and external interfaces.
I have a choke router between our fw internal interface and our real
internal networks. I have a static route for the external network on our
internal router. I have NAT installed on the choke router to overflow on the
external interface, as well as a static NAT for the mgmt station to allow
communication back and forth.

I can ping the fw from the mgmt station, and I can ping the mgmt station
from the fw. 

Now I have problems with the authentication. I think I tried everything. I
added all the addresses, I even did the -n command. Nothing works. I always
get the "authentication failed" or "unauthorized action" message.

I manage other firewalls from that mgmt station, so I can't just turn of
authentication for all of them, but I put in a separate line for the "new"
fw, but it still doesn't work.

Has anybody another idea of how I can get this to work?

Any help appreciated.

Thanks,

Philipp 


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.