| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hi, I have two FW's in my lab, both are Solaris 10 and both have VLANS configured on them $ ifconfig -a lo0: flags=2001000849<UP,LOOPBACK,RUNNING,MULTICAST,IPv 4,VIRTUAL> mtu 8232 index 1 inet 127.0.0.1 netmask ff000000 bge0: flags=1100843<UP,BROADCAST,RUNNING,MULTICAST,ROUTE R,IPv4> mtu 1500 index 2 inet 192.168.10.57 netmask ffffff00 broadcast 192.168.10.255 bge1: flags=1100843<UP,BROADCAST,RUNNING,MULTICAST,ROUTE R,IPv4> mtu 1500 index 3 inet 192.168.100.57 netmask ffffff00 broadcast 192.168.100.255 bge86001: flags=201100843<UP,BROADCAST,RUNNING,MULTICAST,ROU TER,IPv4,CoS> mtu 1500 index 4 inet 192.168.86.57 netmask ffffff00 broadcast 192.168.86.255 bge88001: flags=201100843<UP,BROADCAST,RUNNING,MULTICAST,ROU TER,IPv4,CoS> mtu 1500 index 5 inet 192.168.88.57 netmask ffffff00 broadcast 192.168.88.255 The same is on the other FW except IP's they are .56, both FW's run R62. I am pinging from one FW to another. From 192.168.100 i can ping either interface(.57 can ping .56 and vice versa) , however there is no connectivity on the other vlans 86 & 88. When i try and ping another VLAN all i see if FW1 (.57) accept the ping but the destination FW doesnt record the packet coming in. When pinging on 192.168.100 subnet i see an accept on both FW's The rulebase is ANY ANY Accept, with Accept outgoing packets enabled in the global policy and log implied rules also enabled. When i unload the rulebase i can ping all vlans, so the vlans work and the connecting switch is also configured correctly, there are no drops recorded in tracker, no anti-spoofing no smartdefense. The toplogies on both FW's are defined correctly and were obtained with a get interfaces with topology. Any ideas ? I am going mad trying to work this out and im sure it is something stupid i am overlooking Thanks in advance. |
| |||
| Hi, Thanks for the advice. I have finally figured out what the problem was. I was running R62 on Solaris 10 with the Performance Pack option installed, aparently this does not support VLANS, with the performance pack uninstalled i tried again and it worked fine. Thanks for the help |
![]() |
| Thread Tools | |
| Display Modes | |
| |