NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW-1] gfb: NG not proxying arp correctly?



Hello All,

I'm using NG FP2 on redhat linux and am having a situation whereby:

hide NAT works great:
1) when using automatic arp
2) automatic NAT
3) when hiding behind the fw's external ip


hide NAT does'nt work: 1) when using automatic arp 2) automatic NAT 3) when hiding behind a seperate valid external ip

Due to various political reasons, I need to use hide nat with a seperate
valid ip, but cannot seem to get this to work.
I have ensured that regular internal routing is correct, as well as added
the additional route to route return packets destined to the valid external
ip, to the internal ip of the fw, the ip which communicates with the various
internal subnets.

I've verified through tcpdump & snort on the fw that arp-requests are being
made for the valid external ip in question, but no arp-replies are being
made by the fw.
I've even tried turning off automatic arp and adding a manual arp entry, but
no joy still.
Any ideas?

Kind Regards,

Gabriel




_________________________________________________________________ Chat with friends online, try MSN Messenger: http://messenger.msn.com

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.