CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-08
slash85 slash85 is offline
Junior Member
 
Join Date: 2007-01-30
Posts: 12
Rep Power: 0
slash85 has an average reputation (10+)
Default 1 External interface with 2 IP Addresses

Running Checkpoint with AI (R55)

Hi,

We recently got a new range of IP addresses off our ISP and have assigned two ips to our FW's external interface eg:

Previous IP: 194.178.51.60
Additional IP: 193.189.31.88 (both now on the same nic)

There is a different default gateway with the new range which we have also added to the card, so now we have:

194.178.51.60 255.255.255.240 dg: 194.178.51.59
193.189.31.88 255.255.255.224 dg: 193.189.31.87 (again both on the same nic)

We have another interface(wb1) in the FW which directly connects to a webserver(wb2).

wb1 192.168.34.1 255.255.255.0 dg: 193.189.31.88
wb2 192.168.34.14 255.255.255.0 dg: 192.168.34.1

wb2 has a NAT of 193.189.31.89.

We just have a simple rule in place for now to allow a single static external address to ping 193.189.31.89 but with no success, nothing even shows in the logs.

Internally this all works like a DMZ segregating the webserver off from the main network.

Is this supported? Have I missed something? Have I made any sense?

Thanks for any help,
Slash.
Reply With Quote
  #2 (permalink)  
Old 2007-02-08
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: 1 External interface with 2 IP Addresses

What platform are you running on?

Have you tried to do that in the firewall object, under the ISP tab?
Reply With Quote
  #3 (permalink)  
Old 2007-02-08
slash85 slash85 is offline
Junior Member
 
Join Date: 2007-01-30
Posts: 12
Rep Power: 0
slash85 has an average reputation (10+)
Default Re: 1 External interface with 2 IP Addresses

Hi,

I'm Running Windows 2003 Server. The way i've assigned multiple ips to one NIC was through TCP/IP properties. Do i need to assign this within checkpoint somewhere as well?

Thanks for the reply,

Slash.
Reply With Quote
  #4 (permalink)  
Old 2007-02-08
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: 1 External interface with 2 IP Addresses

Yes you need to add the IP addresses into the gateway's topology
Reply With Quote
  #5 (permalink)  
Old 2007-02-09
slash85 slash85 is offline
Junior Member
 
Join Date: 2007-01-30
Posts: 12
Rep Power: 0
slash85 has an average reputation (10+)
Default Re: 1 External interface with 2 IP Addresses

Nice 1 i'll give this a try on Monday
Reply With Quote
  #6 (permalink)  
Old 2007-02-12
slash85 slash85 is offline
Junior Member
 
Join Date: 2007-01-30
Posts: 12
Rep Power: 0
slash85 has an average reputation (10+)
Default Re: 1 External interface with 2 IP Addresses

Hi,

How can i add this into topology as when i try is says the interface name must be unique? Do i just make up and interface name even tho it states it must match the operating system name exactly?

In topology we have:

q57w2k9 194.178.51.60 255.255.255.240 External

And i've tried to add:

q57w2k9 193.189.31.88 255.255.255.224 External


Thanks for any help,
Slash.
Reply With Quote
  #7 (permalink)  
Old 2007-02-12
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: 1 External interface with 2 IP Addresses

On all operating systems (except windows I think) when you do this you get a virtual interface, which then gets properly imported by Check Point when you do "Get Topology".

Have you tried doing a "Get Topology" since you configured the new IP? Bear in mind that it clears the anti-spoofing config.
Reply With Quote
  #8 (permalink)  
Old 2007-02-13
slash85 slash85 is offline
Junior Member
 
Join Date: 2007-01-30
Posts: 12
Rep Power: 0
slash85 has an average reputation (10+)
Default Re: 1 External interface with 2 IP Addresses

Hi MarioL,

Just tried this but it only picks up the orginal address not both or any kind of virtual interface.

Any other ideas?

Thanks,
Slash.
Reply With Quote
  #9 (permalink)  
Old 2007-02-13
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: 1 External interface with 2 IP Addresses

Hi slash85,

Just re-read all of this. Do you have 2 routers from the same ISP? Or do you only have 2 lines or 2 address blocks?

If the later is the case you don't need to configure more external IP addresses, you can just add a route in your external router to send all the IPs on the new subnet to the firewall's external interface. This means you can then use all the addresses for NAT, etc... even the usual network and broadcast.

If you have 2 routers you could also theoretically use the same address space externally and just assign one of your old external IPs to that new router.

Can you describe a bit better what you want to obtain? I know I'm going out at a tangent here, but after reading it better I realized we might be trying to "fix" the wrong problem.

So I guess I'm kind of answering with questions, but...
Do you have specific restrictions on what you can do?
How many routers? How many lines? Apparently 2 dif. public IP subnets.
What is the ultimate goal?
Reply With Quote
  #10 (permalink)  
Old 2007-02-14
slash85 slash85 is offline
Junior Member
 
Join Date: 2007-01-30
Posts: 12
Rep Power: 0
slash85 has an average reputation (10+)
Default Re: 1 External interface with 2 IP Addresses

Hi MarioL,

Yes there are two external routers from the same ISP which we have no control over all manged by them, both with different subnets. And yes we have two block of addresses the old and new.

Do you think that maybe the 2nd router is forwarding traffic to the original external FW IP(194.178.51.60) and not 193.189.31.88? Maybe speak to the ISP?

All in all the ultimate goal is to have both old and new IP range working through the one external interface on the FW.

Thanks,
Slash
Reply With Quote
  #11 (permalink)  
Old 2007-02-15
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: 1 External interface with 2 IP Addresses

OK, cool.

Considering this is windows, what I'd go for:
- Leave FW with only 1 external IP
- Get provider to configure internal interface of new router with a free IP from the existing public range (old)
- Get provider to route all the new subnet to the FW's external IP
- Configure 2 ISP lines in the Topology ISP bit

You will need to configure some manuals NATs for the servers to respond by 2 dif public IPs and possibly some tricky routing if you want to use both lines.

To be honest, windows is not the ideal platform to make the best of the 2 lines, since it doesn't support source routing AFAIK.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:05.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0