CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Licensing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-12
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 534
Rep Power: 10
BarryStiefel has disabled reputation
Default What to put in $FWDIR/conf/external.if

What to put in $FWDIR/conf/external.if



This file should contain the physical device name. You can get this by doing an ifconfig (Unix/IPSO/Linux) or ipconfig (NT/W2000). Example interface names include: le1, El90x1 (as in the letter E, the letter l, the number 9, the number 0, the letter x, and the number 1). On a Nokia platform, this should contain the physical interface name plus c0 (e.g. eth-s1p1c0).

The external interface is often the interface facing your Internet router. If you have more than one external interface, you should be using an unlimited node license, or upgrade to NG, which supports multiple external interfaces.

-- PhoneBoy - 02 Jan 2004

FAQForm FAQs.Class: LicensingFAQs FAQs.OS: FAQs.Version: 4.1
Reply With Quote
  #2 (permalink)  
Old 2006-06-12
zyz101z zyz101z is offline
Junior Member
 
Join Date: 2006-06-07
Posts: 12
Rep Power: 0
zyz101z has an average reputation (10+)
Default Re: What to put in $FWDIR/conf/external.if

Does anyone know if this file is still needed in NGX? I dont have it on any of my firewalls. Although on the pair I have that dont have unlimited liscenses I am having problems where on one its showing 3000+ hosts. Which shouldnt be possible as there are only 2 interfaces. One, which leads to my DMZ firewalls, is marked as external in the firewall object. The other is a /23. Looking at the hosts, it does seem to be seeing objects that should be behind the external IP. I wanted to confirm this file was still required before I added it.

Thanks
Reply With Quote
  #3 (permalink)  
Old 2006-06-13
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 434
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: What to put in $FWDIR/conf/external.if

If you experience problems with too many hosts then you should create the file according to instructions above, even on NGX. (the file is not there by default)
Reply With Quote
  #4 (permalink)  
Old 2006-06-23
cschwab1 cschwab1 is offline
Junior Member
 
Join Date: 2006-06-21
Posts: 1
Rep Power: 0
cschwab1 has an average reputation (10+)
Default Re: What to put in $FWDIR/conf/external.if

Regarding the external.if file and NGX, does NGX not create this file as does NG AI? What about the fwd.h and fwd.hosts files, are this not created by default in NGX? Has the method that NGX uses to track the hosts the firewall is protecting change from NG AI to NGX?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:21.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0