CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Installing And Upgrading
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-19
Junior Member
 
Join Date: 2008-01-17
Posts: 19
Rep Power: 0
CPone has an average reputation (10+)
Default Adding Public IP from different Ranges

I’m facing some routing issues with checkpoint and I would appreciate if someone can help on this. Here are the details of the problem:



we received a list of valid IP addresses from our ISP in 2001. The IPs were 213.x.y.z /29. We used one of the Valid IP addresses to setup the external interface of our Checkpoint firewall and appropriate licenses accordingly. The remaining IPs were used to host servers and services within our DMZ zone by NATing them behind the firewall. This worked perfectly.



In 2007, we required more valid IP addresses to accommodate additional Internet servers, therefore we requested for additional IP addresses from our ISP. they provided 213.x.y.z /29 (not directly comming after the one we had) to be used by us. According to the ISP, this subnet uses the same upstream gateway as the previous set of IPs.

If I assign one of the new valid IPs to the external interface of the firewall (as a secondary IP), I can ping the interface from the Internet. But when I use one of the valid IPs to host a server in our DMZ zone, I cannot ping that host.

We have some related server that is DESPERATELY waiting to be hosted on the Internet. Please any clue why it is not working?
Reply With Quote
  #2 (permalink)  
Old 2008-01-20
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Adding Public IP from different Ranges

On Nokia? Did you add a proxy ARP entry on the Nokia for that new server IP address?

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-01-21
Junior Member
 
Join Date: 2008-01-17
Posts: 19
Rep Power: 0
CPone has an average reputation (10+)
Default Re: Adding Public IP from different Ranges

actually it is checkpoint on windows.
Reply With Quote
  #4 (permalink)  
Old 2008-01-21
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Adding Public IP from different Ranges

Sorry, I don't have any experience with firewalls on Windows. It still sounds like an ARP problem, though. On SPLAT you would use "fw ctl arp" to see if the ARP is correct. I'm guessing it will work on Windows, but I don't know.

Ray
Reply With Quote
  #5 (permalink)  
Old 2008-01-21
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: Adding Public IP from different Ranges

It has been a long time since I worked with CP on a Windows gateway.. But have you added a route for the external ip to the internal ip on the gateway?

route add -p 207.123.123.123 mask 255.255.255.255 192.168.1.123

Where 207.123.123.123 is the public IP of your host and 192.168.1.123 is the internal IP.
Reply With Quote
  #6 (permalink)  
Old 2008-01-21
Junior Member
 
Join Date: 2008-01-17
Posts: 19
Rep Power: 0
CPone has an average reputation (10+)
Default Re: Adding Public IP from different Ranges

well what i did is i have added another network card on the server and i gave it a IP from the new subnet and it worked,

i did not try the route, thanks anyway
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:05.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0