CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-04-10
Junior Member
 
Join Date: 2005-12-11
Location: Dubai, UAE
Posts: 20
Rep Power: 0
ilmaz has an average reputation (10+)
Default NGX Gateway & DHCP Relay Agent

Hi evb,

I'm looking forward to make se of the NGX SPLAT's DHCP Relay Agent option configurable through Sysconfig.

I've got a DHCP/DNS Server available in my DMZ (eth1) and would like to let my clints from Net1 (eth2) and Net2 (eth3) to recieve automatic IP config from that DMZ DHCP server.

Through Sysconfig I configured the DHCP Relay Agent option and specified eth2 & eth3 to operate as DHCP Relay agents and I also configured DHCP Server's address accessible through eth1 properly. Then I added rule to allow dehcp-req-localmodule, dhcp-rep-localmodule, and bootp services to be allowed from Net1 & Net2 to the SPLAT Gateway.

However, it staill doesn't work and I can see that dhcp-req-localmodule is being dropped by the SPLAT Gateay, anybody has any idea how to get it working??????

Regards,
Ilmaz
__________________
Ilmaz S.Kashkooli (Kory)
Reply With Quote
  #2 (permalink)  
Old 2006-05-01
Junior Member
 
Join Date: 2006-01-24
Posts: 26
Rep Power: 0
yipster has an average reputation (10+)
Default Re: NGX Gateway & DHCP Relay Agent

you need to setup a static NAT to allow the private network to see the dmz dhcp server
Reply With Quote
  #3 (permalink)  
Old 2006-05-02
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,660
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: NGX Gateway & DHCP Relay Agent

Quote:
Originally Posted by ilmaz
Hi evb,

I'm looking forward to make se of the NGX SPLAT's DHCP Relay Agent option configurable through Sysconfig.

...
It's broken, AFAIK it hasn't been kixed in an HFA but I may be wrong. You should be able to remove the DHCPD package and add the one from the R55 CD's.
Reply With Quote
  #4 (permalink)  
Old 2006-05-09
Junior Member
 
Join Date: 2006-01-24
Posts: 26
Rep Power: 0
yipster has an average reputation (10+)
Default Re: NGX Gateway & DHCP Relay Agent

Jim,

Where is the DHCPD located in the R55 disc
Reply With Quote
  #5 (permalink)  
Old 2006-05-10
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: NGX Gateway & DHCP Relay Agent

SecurePlatform\RPMS\dhcpcd-1.3.18pl8-14cp.i386.rpm
Reply With Quote
  #6 (permalink)  
Old 2006-05-10
Junior Member
 
Join Date: 2006-01-24
Posts: 26
Rep Power: 0
yipster has an average reputation (10+)
Default Re: NGX Gateway & DHCP Relay Agent

I had to call tech support to email me the dhcrelay file which replaces the one in /usr/sbin directory.
Reply With Quote
  #7 (permalink)  
Old 2006-11-18
Junior Member
 
Join Date: 2006-01-24
Posts: 26
Rep Power: 0
yipster has an average reputation (10+)
Default Re: NGX Gateway & DHCP Relay Agent

DHCP Relay doesn't work in R62 same problem in R60. I had to use dhcrelay file inorder for it to work. What is going on with Checkpoint.
Reply With Quote
  #8 (permalink)  
Old 2007-01-17
Junior Member
 
Join Date: 2006-09-29
Posts: 17
Rep Power: 0
hono222 has an average reputation (10+)
Default Re: NGX Gateway & DHCP Relay Agent

Hi,

It does work in R60...it works for me
Reply With Quote
  #9 (permalink)  
Old 2007-03-01
Junior Member
 
Join Date: 2006-03-10
Location: Detroit Michigan USA
Posts: 15
Rep Power: 0
dr-spoof has an average reputation (10+)
Default Re: NGX Gateway & DHCP Relay Agent

In VSX I had to create static NAT from the wrp interfaces to the inside real address for udp 68 for this to work properly. The windows fw was having a hard time due to the original PATing and the port numbers instead of being 68 were some high numbers generally starting around 700 and up. This is all on SPLAT.

I have it working well so far in a remote server situation, but it's not working in a multi-vlan case where the server is on one vlan and the host on another on the same VS. This message shows up in the messages file.

kernel: FW-1: fwx_handle_dhcp_payload: ld_set(fwx_dhcp_relay) failed

No one knows what it is.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 08:32.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0