CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-13
flontous flontous is offline
Junior Member
 
Join Date: 2007-04-22
Posts: 5
Rep Power: 0
flontous has an average reputation (10+)
Default Routing Issue between firewalls

Got a problem routing from two LANS on separate interfaces on one firewall to another LAN on a different firewall. IPSO4_2 & CPR_62.

Here is the diagram and ruleset (any service between LANS).
LAN3 10.226.16.0/23
LAN1 10.226.193.0/24
LAN2 10.226.194..0/24
DRS Link is a direct connection over microwave - 10.226.192.0/24
FW1 = main corporate
FW2 = Disaster Recovery Site

Ping/Traceroute don't make it to hosts behind FW1 from hosts behind FW2.

Will need to recheck the routing tables on both firewalls to verify.

From FW2 - Internet access and FW3 routing are alright!

What do you think?
Attached Images
File Type: jpg error.JPG (27.5 KB, 129 views)

Last edited by flontous; 2007-05-13 at 18:55. Reason: add more info
Reply With Quote
  #2 (permalink)  
Old 2007-05-13
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 895
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Routing Issue between firewalls

> What do you think?

I don't know what the problem is. Can you give an example, please?

Since these are private addresses, would you please put all of the numbers in?

What does DRS stand for?

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-05-14
flontous flontous is offline
Junior Member
 
Join Date: 2007-04-22
Posts: 5
Rep Power: 0
flontous has an average reputation (10+)
Default Re: Routing Issue between firewalls

FW1 Routing Table:
10.5.1.0/24 eth-s2p2c0 CGUX eth-s2p2c0
10.5.1.0 eth-s2p2c0 CGHU eth-s2p2c0
10.5.1.1 eth-s2p2c0 CGHU eth-s2p2c0
10.5.1.7 CGHLU eth-s2p2c0
10.5.1.40 0:9:8a:1:1:f6 CGHLU eth-s2p2c0
10.5.1.40 10.5.1.40 HLUW eth-s2p2c0
10.5.1.42 0:9:8a:1:1:f5 CGHLU eth-s2p2c0
10.5.1.70 0:d:60:4e:a:b3 CGHLU eth-s2p2c0
10.5.1.109 0:9:8a:1:10:56 CGHLU eth-s2p2c0
10.5.1.110 0:9:8a:1:10:57 CGHLU eth-s2p2c0
10.5.1.111 0:9:8a:1:10:58 CGHLU eth-s2p2c0
10.5.1.245 0:d:60:9c:bb:b9 CGHLU eth-s2p2c0
10.5.1.255 eth-s2p2c0 CGHU eth-s2p2c0
10.226.192.0/24 eth1c0 CGUX eth1c0
10.226.192.0 eth1c0 CGHU eth1c0
10.226.192.1 0:a0:8e:7b:90:b0 CGHLU eth1c0
10.226.192.2 eth1c0 CGHU eth1c0
10.226.192.255 eth1c0 CGHU eth1c0
10.226.193.0/24 eth1c0 CGUX eth1c0
10.226.193.0 eth1c0 CGHU eth1c0
10.226.193.1 eth1c0 HUWX eth1c0
10.226.193.2 eth1c0 CGHU eth1c0
10.226.193.9 eth1c0 RCGHU eth1c0
10.226.193.9 10.226.193.9 RHUW eth1c0
10.226.193.17 eth1c0 HUWX eth1c0
10.226.193.255 eth1c0 CGHU eth1c0
10.226.194.0/24 eth1c0 CGUX eth1c0
10.226.194.0 eth1c0 CGHU eth1c0
10.226.194.2 eth1c0 CGHU eth1c0
10.226.194.255 eth1c0 CGHU eth1c0

The 10.5.1.0/24 network is the Local SAN. I need to route from there to 10.226.194.0?

Going to get the FW2 Routing table shortly
Reply With Quote
  #4 (permalink)  
Old 2007-05-14
sail4fun sail4fun is offline
Member
 
Join Date: 2006-07-16
Posts: 49
Rep Power: 0
sail4fun has an average reputation (10+)
Default Re: Routing Issue between firewalls

Any clue in smartviewtracker logfiles ?
Antispoofing ?
Reply With Quote
  #5 (permalink)  
Old 2007-05-14
flontous flontous is offline
Junior Member
 
Join Date: 2007-04-22
Posts: 5
Rep Power: 0
flontous has an average reputation (10+)
Default Re: Routing Issue between firewalls

Look like the packets are going from the internal network, out the external interface, and then back into the firewall for delivery to the destination over the proper interface. Or they are picking up the external ip due to NAT, but I don't have that configuration set up.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 10:42.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0