Re: [FW-1] IPv6 problems

2012-10-01 Thread Giacomo Fazio

Solved!!!

I had to route the gw to fw external interface

-Messaggio originale- 
From: Tarmo Mamers

Sent: Monday, October 01, 2012 6:50 AM
To: FW-1-MAILINGLIST@AMADEUS.US.CHECKPOINT.COM
Subject: Re: [FW-1] IPv6 problems

Again: what do you see in the firewall logs with IPv6 filter? (If anything 
at all)


Next: Do you get Cisco's MAC into firewall neighbor table (ip -6 neigh) 
after generating some v6 traffic? Do you get Gaia's MAC into Cisco's 
neighbor table (sh ipv6 neigh)? Of course, answers to these both questions 
should be the same :P


Then: Do you see any v6 traffic on the firewall interfaces (tcpdump -i any 
ip6) when generating some v6 traffic? Do you get any v6 traffic dropped and 
why on the firewall (fw6 ctl zdebug + drop)?



Cheers
-tarmo-
Scanned by Check Point Total Security Gateway.

=
To set vacation, Out-Of-Office, or away messages,
send an email to lists...@amadeus.us.checkpoint.com
in the BODY of the email add:
set fw-1-mailinglist nomail
=
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=
If you have any questions on how to change your
subscription options, email
fw-1-ow...@ts.checkpoint.com
= 



Scanned by Check Point Total Security Gateway.

=
To set vacation, Out-Of-Office, or away messages,
send an email to lists...@amadeus.us.checkpoint.com
in the BODY of the email add:
set fw-1-mailinglist nomail
=
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=
If you have any questions on how to change your
subscription options, email
fw-1-ow...@ts.checkpoint.com
=


Re: [FW-1] IPv6 problems

2012-09-30 Thread Tarmo Mamers
Again: what do you see in the firewall logs with IPv6 filter? (If anything at 
all)

Next: Do you get Cisco's MAC into firewall neighbor table (ip -6 neigh) after 
generating some v6 traffic? Do you get Gaia's MAC into Cisco's neighbor table 
(sh ipv6 neigh)? Of course, answers to these both questions should be the same 
:P

Then: Do you see any v6 traffic on the firewall interfaces (tcpdump -i any ip6) 
when generating some v6 traffic? Do you get any v6 traffic dropped and why on 
the firewall (fw6 ctl zdebug + drop)?


Cheers
-tarmo-
Scanned by Check Point Total Security Gateway.

=
To set vacation, Out-Of-Office, or away messages,
send an email to lists...@amadeus.us.checkpoint.com
in the BODY of the email add:
set fw-1-mailinglist nomail
=
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=
If you have any questions on how to change your
subscription options, email
fw-1-ow...@ts.checkpoint.com
=