CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-23
Junior Member
 
Join Date: 2007-10-23
Posts: 4
Rep Power: 0
free1688 has an average reputation (10+)
Default Routing problem between two firewalls ?

Hi,

I'm new in checkpoint.
pc1 ip : 192.168.1.1

fw1 ip1 : 192.168.1.254
fw1 ip2 : 192.168.2.254

fw2 ip2 : 192.168.2.253
fw2 ip1 : 192.168.3.254

pc2 ip : 192.168.3.1

pc1 <-> fw1 <-> fw2 <-> pc2

i can't ping & traceroute from pc1 to pc2 and vice versa. why?
i already create a static route in fw1 & fw2.
any suggestion ?

thx
Reply With Quote
  #2 (permalink)  
Old 2007-10-24
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Routing problem between two firewalls ?

OK what platform is this running on so that we can get an idea of how to add possible stuff.

Are we correct in understanding that the routing is correct in as much as that PC1 uses fw1 as it's default gateway and that fw1 uses fw2 as it's.

Also that PC2 uses fw2 as it's DG and fw2 uses fw1 as it's.

What are you seeing in the SMARTView Tracker regarding ICMP, does your security policy even allow ICMP through the firewall.
Reply With Quote
  #3 (permalink)  
Old 2007-10-24
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 146
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: Routing problem between two firewalls ?

Hi
Well all the issue is with the gateway setting in the systems as well as the default gateway in Firewall.Its not a much complex network, if some routers and switches are there in between then better clear there ARP.
If you want some more help, just let me know the system IP settings.

I hope its not a big issue.

Regards
Ranjit
Reply With Quote
  #4 (permalink)  
Old 2007-10-24
Junior Member
 
Join Date: 2007-10-23
Posts: 4
Rep Power: 0
free1688 has an average reputation (10+)
Default Re: Routing problem between two firewalls ?

hi,

fw1 & fw2 checkpoint NGR65 secure platform
policy: any any accept
no nat

fw1 ip1 : 192.168.1.254
fw1 ip2 : 192.168.2.254
static route: route 192.168.3.0/24 via 192.168.2.253
default gw : 192.168.1.254

fw2 ip2 : 192.168.2.253
fw2 ip1 : 192.168.3.254
static route: route 192.168.1.0/24 via 192.168.2.254
default gw : 192.168.3.254

pc1 ip : 192.168.1.1 gw: 192.168.1.254
pc2 ip : 192.168.3.1 gw: 192.168.3.254

pc1 <-> fw1 <-> fw2 <-> pc2

thx
Reply With Quote
  #5 (permalink)  
Old 2007-10-24
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Routing problem between two firewalls ?

I presume when you say that the DG is the interface of the firewall that you are talking about the DG for the PC rather then the DG for the Firewall.

Looking at it however then the routing is not the issue and is that your policy does not allow ICMP through.

ICMP does not match the any on an accept rule. You either need to specifiy to allow ICMP through or enable under Global Properties on the Policy menu.

Whilst Any means Any on a drop it does not mean so on an Accept rule. Hence the Match for 'Any' under the advanced section for service definitions.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:57.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0