CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Sun Solaris
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-08-03
elblindo elblindo is offline
Junior Member
 
Join Date: 2006-01-12
Posts: 5
Rep Power: 0
elblindo has an average reputation (10+)
Default VLAN tagging and FW1 NGX 6.0

Hello,

I have to solve a strange problem with solaris 10/01 and FW1 NGX60.
I've a tagged vlan switch-port (vlans 40 and 50) connected to a ce-quadcard-port and configured two vlans as ce40005 and ce50005, as supposed by SUN-manpages.
If CP FW1 is down, the vlans can connect as expected, if FW1 is up, the following mysterious behaviour occur :

- a Ping from physical interface ce3 to a physical interface ce0 = success
- a Ping from physical interface ce3 to a vlan-interface ce50005 = error (i can see a echo-request with snoop)
- a Ping from Client connected to vlan 50 to an address behind ce3 = error ( i can see a echo-request from vlan-client and echo-response from destination on interface ce3, but no echo-response on vlan-interface ce50005)
- a Ping from Client connected to vlan 40 to an address on vlan 50 = error (I can snoop only a echo-request in ce40004, no echo-response)

The ruleset allows ping to all the source and dests, an the log shows the incoming request as accepted.

Is there anything I forgot to successful configure vlans on CP-Fw1?

Thanks in advance

elblindo
Reply With Quote
  #2 (permalink)  
Old 2006-08-07
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: VLAN tagging and FW1 NGX 6.0

Check the anti-spoofing
Reply With Quote
  #3 (permalink)  
Old 2006-08-08
elblindo elblindo is offline
Junior Member
 
Join Date: 2006-01-12
Posts: 5
Rep Power: 0
elblindo has an average reputation (10+)
Default Re: VLAN tagging and FW1 NGX 6.0

Hello chillyjim,

Thanks for your response.
I checked the smartdefense-setting twice, incl. antispoofing, enabled and disabled it on all interfaces, made topology-update with no success at all. I set all smartdefense-filters to "log only", nothing happens other than before.
It seems, that the pakets were not routed. My last post was a little bit wrong that way. If FW1 is down, I can ping its vlan-interfaces ce50005 and ce40005, but not devices in subnets behind these interfaces. Therefor I decided to make a fresh install of Solaris 10. Without installation of FW1 the pakets were routed. Until now there wasn't time to newly setup FW1 on this new Solaris-installation.

If I make further (successful) steps, I will report here.

Regards

elblindo
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 16:52.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0