[FW-1] Nat

2004-09-03 Thread Lopez Zambrano, David
Hi, I'm trying to set a simple nat on my system (WNT + CP4.1 is a little older, i know...). but it doesn't works, what i'm doing wrong? I define a physical machine (ip 192.168.201.243 internal ip let's call srv1) and on nat settings: valid ip: 195.77.175.69 (let's call this Web1), and add auto

[FW-1] Réf. : [FW-1] Nat

2004-09-03 Thread Bertrand KLOTZ
Hi You must - add a route from valid address to internal address - have an entry in your FWDIR\state\local.arp file with: valid_address external_mac_address - reboot your FW1 Bertrand Lopez Zambrano, David [EMAIL PROTECTED] le 03-09-2004 11:15:37 Veuillez répondre à Mailing list for

Re: [FW-1] Nat

2004-09-03 Thread Robert Plaenk
You need to add a host route on your firewall, and you also need to ARP for the external address. Another thing...autmatic NAT has a tendency to break in v4.1. I would recommend manual NAT. It's a little more work, but it's rock solid. -Original Message- From: Mailing list for

[FW-1] SecurePlatform and VPN Accelator cards?

2004-09-03 Thread Previtera, Sal
Hello Everyone, Has anyone able to use any IPSEC accelerator cards with the SecurePlatform? Checkpoint Accelerator Card III does not seem to be supported in SPLAT. I wonder why?. Since both are Checkpoint products. I have opened a TAC case with support but I am think I already know what they

[FW-1] RE: [FW-1] Re: [FW-1] Réf. : [FW-1] Nat

2004-09-03 Thread Robert Plaenk
That's fine, if you have it routed. It works fine that way too. You will still need to add a route on the FW from your external valid IP to the internal IP. -Original Message- From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On Behalf Of Joao Santos Sent:

[FW-1] Site-to-Site VPN Traffic monitoring in depth

2004-09-03 Thread Wayne Ho
Does anyone know how to monitor Site-to-Site VPN communication traffic? User experiences lot of packet drop during site-to-site VPN connection (Only VPN, not Internet, they are using split traffic). The connection is between NG FP3 and Netopia DSL router. SmartView Tracker can't show any more

[FW-1] VPN routing question

2004-09-03 Thread Ray
I just set up a test VPN from an R55 gateway to an Edge XU box and I now have my computer on it's internal network. When I have SecureClient running on my computer, I can't get to the real internal network. I have to disable the policy, even though this new internal network is allowed in the

[FW-1] Nating Problem

2004-09-03 Thread NAVTEJ KOHLI
Hi Firewall gurus, I have a problem in Nating. I restart my firewall then it stop nating services? I have a Checkpoint AL on Solaris. This problem has started recently. All my internal addresses are effectively non-routable. I changed one rule which NATed a single machine in my network. When I

[FW-1] Intersection with User Database feature lost in Simplified Mode ?

2004-09-03 Thread Nguyen, Thai
Hi all, I am planning to finally migrate my NG AI rule base from Traditional to Simplified mode. In my lab tests with a Simplified mode rule base, I find that the Do/Do Not Intersect with User Database option found in the Client Encrypt properties no longer seems to be present. Two dumb