CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Licensing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-07-31
Junior Member
 
Join Date: 2006-07-17
Posts: 10
Rep Power: 0
Fabsta has an average reputation (10+)
Default Multiple External Interfaces

Peoples - I am having a little problem at the moment. I am currently migrating ISPs and have configured a 2nd external interface on my Checkpoint NGX x45 Crossbeam appliance. It is a clustered interface of which all the rest work perfectly. The problems lies in connecitivty - I can add the intereface perfectly, but then I can connect to it Ok for about 8 or so hrs, and then I cant even get an arp reponse back from it even from the next hop.

The arp table just gives me INCOMPLETE on the router (next hop). Its almost like it doesnt see it at all - I can however ping it from with internal segments, but coming from external, it just doesnt seem to exist. Its like its put the Interface into a type of promiscuos mode for all traffic originating externally.

I have only a 500 node license, and was wondering if I'm allowed 2 external interfaces. Any information would greatly be appreciated. Also any secure client sitre created after I added the 2nd external interface doesnt seem to work at all - I have to delete the 2nd interface and the site can then be connected etc. Secure client issue aside, I really just wanted to know if I can have multiple external interfaces defined - and if so why it deosnt seem to work properly

Kind Regards,
Fab
Reply With Quote
  #2 (permalink)  
Old 2006-08-01
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 854
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Multiple External Interfaces

You can have multiple external interfaces with a node-limited license - you just can't forward traffic from one external interface to another.

You should be seeing it in your logs if you've got license problems anyway.

What's happening with ARP? Is the router sending an ARP request, and the firewall just ignoring it? Or is the firewall sending a response, but the router doesn't like the response?
Reply With Quote
  #3 (permalink)  
Old 2006-08-01
Junior Member
 
Join Date: 2006-07-17
Posts: 10
Rep Power: 0
Fabsta has an average reputation (10+)
Default Re: Multiple External Interfaces

Yeah its a bit weird - It seems to work for a little while - I see traffic hitting me and all is working, then for some unknown reason I test again and everything isnt working and I dont even get an arp reply from the FW.

Routers arp table entry is just set to 'INCOMPLETE', where it had returned the mac address previously. I even reset router interface and it doesnt help.

Strange behaviour.
Reply With Quote
  #4 (permalink)  
Old 2006-08-01
Junior Member
 
Join Date: 2006-07-17
Posts: 10
Rep Power: 0
Fabsta has an average reputation (10+)
Default Re: Multiple External Interfaces

Case closed - the crossbeam linux FW had the broadcast address as my nexthop which is actually wrong, but I change the next hop address to somethinglower and all is good.

Cheers
Fab
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 08:50.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0