CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point VPN-1 Edge Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-29
munrog munrog is offline
Member
 
Join Date: 2006-06-27
Location: New Zealand
Posts: 70
Rep Power: 3
munrog has an average reputation (10+)
Send a message via MSN to munrog Send a message via Skype™ to munrog
Default EdgeX and ARPs

Hi Folks,
I'm having problems with an Edge ADSL box and ARP. Basically I have two public IP addresses. One is on the external the other on the DMZ port and an RFC1918 on the LAN port. My problem is that I have an IPSEC tunnel endpoint on the DMZ, but I cannot seem to communicate with it. If I sniff the traffic I see that the ISPs equipment is issuing an ARP who-has for the IPSEC tunnel device, but the Edge box is not responding. I've tried specific rules allowing the traffic through to the device, I've tried setting it up as an IPSEC VPN server and I've tried making it an "exposed host". None of these seems to resolve the issue of no reponse to the ARP. Is there a way to tell the Edge box to act as a proxy arp?

Or should it be that the ISP shouldnt be issuing an ARP who-has? This is PPPoATM not PPPoE...

Ta in advance
Greg

Last edited by munrog; 2007-05-29 at 09:48.
Reply With Quote
  #2 (permalink)  
Old 2007-05-29
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 139
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: EdgeX and ARPs

If you have only 2 public IP' ask the provider to create a static route to the second public IP.
If possible talk direct to the technical stuff (most can solve your problem during you phone with them).
Reply With Quote
  #3 (permalink)  
Old 2007-05-29
munrog munrog is offline
Member
 
Join Date: 2006-06-27
Location: New Zealand
Posts: 70
Rep Power: 3
munrog has an average reputation (10+)
Send a message via MSN to munrog Send a message via Skype™ to munrog
Default Re: EdgeX and ARPs

Sorry I meant, I have two public IP Address RANGES. One for the Internet Side and one for the DMZ side. Basically, with sniffer I am seeing "ARP who-has" requests on the WAN side for the IP address of the host on the DMZ, but I am not seening any "ARP reply". I do not see any corresponding packets on the DMZ interface whatsoever.
Reply With Quote
  #4 (permalink)  
Old 2007-05-29
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 139
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: EdgeX and ARPs

I only know that the edge do arp if you have configured nat between a public and a private IP.
But the routing works with ipranges to.

for example
first public range is. 192.168.1.0/28 (edge is 192.168.1.2)
second range is 192.168.1.16/28 (dmz network with public IP)

the provider can create a route like this at his site 192.168.1.16/28 gw 192.168.1.2.

Since the edge know the route from the topo to the 192.168.1.16/28 network the traffic will flow to the dmz interface.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 09:21.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0