Hi,
install a file named local.arp in the directory $FWDIR\state
In plain ASCII you should write in this file
 dstaticIPaddress M-A-C-a-d-d-r-e-s-s
The first entry is the translated IP address, the MAC address is the MAC of the
external interface of your FW. The hex-numbers are separated by "-", not by ":" as
in Unix.
If you need another address to be translated, just add a new line with the second IP
and the same MAC.
After editing the local.arp you will have to restart the FW.
Other problems may occur if you don't have set up the routing for the translated IP
address. For the translated IP you need a static route to the internal (DMZ-)
machine. The NAT will be done at the internal NIC, so you also have to adapt the
Anti-Spoofing for this interface.
Hope it helps,
best regards
Matthias

[EMAIL PROTECTED] wrote:

> Hi all,
>
> I've been installing triple homed (internal, dmz, external) FW-1 4.1 on an
> NT box, and everything went fine except for  the ability to see the boxes
> in the DMZ from the outside. I strongly suspect the problem is with the
> local.arp file I set up, I have heard stories that the process is a bit
> unreliable...does anybody have or know of a procedure that will definitely
> work for local.arp on NT?
>
> Ian Turner
>
> **********************************************************************
> This email and any files transmitted with it are confidential and
> intended solely for the use of the individual or entity to whom they
> are addressed. If you have received this email in error please notify
> the system manager.
>
> This footnote also confirms that this email message has been swept by
> MIMEsweeper for the presence of computer viruses.
>
> SCEE
> **********************************************************************
>
> ================================================================================
>      To unsubscribe from this mailing list, please see the instructions at
>                http://www.checkpoint.com/services/mailing.html
> ================================================================================
begin:vcard 
n:Leu;Dr. Matthias
tel;cell:+49 172 8943533
tel;fax:+49 89 697 59 396
tel;work:+49 89 697 59 390
x-mozilla-html:FALSE
url:http://www.aerasec.de
org:AERAsec Network Services and Security GmbH (iG)
adr:;;Wagenberger Str. 1;Hohenbrunn b. Muenchen;;D-85662;Germany
version:2.1
email;internet:[EMAIL PROTECTED]
fn:Dr. Matthias Leu
end:vcard

Reply via email to