For static NAT in a VRRP environment (which I believe you are talking
about), we did the following:
1) Instead of using proxy arp, we created a "backup" VRRP address.
According to some doc I recently read, this is the preferred method.
2) Create a static route to marry the addresses together i.e. outside
backup vrrp address ------ real host address
3) Create the appropriate rule in the rulebase and the address translation
rule.
For HIDE NAT in a VRRP environment, we did the following:
1) See above
2) Create the approriate rule in the address translation table using the
created VRRP backup address to hide behind.
Regards................Elliot
"Thomas Stala" <[EMAIL PROTECTED]>@lists.us.checkpoint.com on 02/11/2001
11:21:50 PM
Please respond to <[EMAIL PROTECTED]>
Sent by: [EMAIL PROTECTED]
To: "Chris Arnold" <[EMAIL PROTECTED]>,
<[EMAIL PROTECTED]>
cc:
Subject: RE: [FW1] VRRP and NAT
Well when I setup the hide I used the real IP of the external interface.
I was told that using static routing with VRRP you should use proxy for the
ARP and the VRRP MAC address.
Please if this is not correct someone please correct me. ;-}
I am new to the Nokia world
Thomas Stala
[EMAIL PROTECTED]
Hope this helps
-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Chris
Arnold
Sent: Tuesday, January 09, 2001 4:46 PM
To: [EMAIL PROTECTED]
Subject: [FW1] VRRP and NAT
Uh oh, doesn't look like I can do hide behind NAT on my VRRP (MC) virtual
address for my external interfaces. PLEASE correct me if I'm wrong.
Chris
============================================================================
====
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
============================================================================
====
================================================================================
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
================================================================================
================================================================================
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
================================================================================