CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-25
iorek iorek is offline
Junior Member
 
Join Date: 2006-12-05
Posts: 13
Rep Power: 0
iorek has an average reputation (10+)
Default Subnetting issue? Can only access 8 out of 16 addresses

Hi,

We've just moved to a new ISP, and from 8 routable IP addresses to 16. I've got the firewall working ok (NGX on Nokia IPSO so I'm accessing the network settings through Voyager interface) but can only use 8 out of the 16 new addresses. I thought it might be a subnetting problem but I'm not sure where I've gone wrong. My other thought is that we used to have 8 addresses and now I can only use 8, so maybe there's some setting I'm missing. I didn't do the original config on the firewall.

Old config:
IP range 217.xxx.xxx.96 - 103
fw IP 217.xxx.xxx.98
next hop static route 217.xxx.xxx.97
destination range 217.98/29 (I assumed it should have started at 96 not 98)

New config:
IP range 195.xxx.xxx.176 - 191
fw IP 195.xxx.xxx.178
next hop static route 195.xxx.xxx.177
destination range 195.xxx.xxx.176/28

When I ping one of the 'unreachable' addresses I don't see anything logged on the firewall.

I'm going to be able to have some downtime to do some testing on Friday - any suggestions gratefully received!

iorek
Reply With Quote
  #2 (permalink)  
Old 2007-07-25
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Subnetting issue? Can only access 8 out of 16 addresses

Check the topology of the firewall's object to make sure it has the new netmask in it.
Reply With Quote
  #3 (permalink)  
Old 2007-07-26
auroranl auroranl is offline
Junior Member
 
Join Date: 2007-05-08
Posts: 22
Rep Power: 0
auroranl has an average reputation (10+)
Default Re: Subnetting issue? Can only access 8 out of 16 addresses

I asume you setup ARP on all addresses? Try removing them and adding one at the time only.

Add a test PC to the interface in question (with the IP in the subnet, eg the one from the router in front). Start a tcpdump on the firewall on the WAN interface and ping all IP's from the laptop for which the firewall should respond (eg has a proxy ARP). Check if the firewall sees any ARP request and response to them.
Reply With Quote
  #4 (permalink)  
Old 2007-07-26
iorek iorek is offline
Junior Member
 
Join Date: 2006-12-05
Posts: 13
Rep Power: 0
iorek has an average reputation (10+)
Default Re: Subnetting issue? Can only access 8 out of 16 addresses

Hi again,

Thank you both for very helpful replies.

chillyjim - you were completely right - I han't changed the net mask on the firewall object.

Thank you!!

iorek
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:58.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0