CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-24
Junior Member
 
Join Date: 2006-11-08
Posts: 19
Rep Power: 0
geelkabouter has an average reputation (10+)
Default Cannot route between internal interfaces

I have setup a new interface with network 192.168.x.x behind it,it needs to access a network 172.16.10.x which sits behind a router 172.16.6.1 i have an interface on the 172.16.6.x range but i am unable to access it from my 192.168.x.x range but I can access it from the 172.16.6.x interface,doesnt seem to route between the two

Any ideas?R65 cluster
Reply With Quote
  #2 (permalink)  
Old 2007-10-24
Senior Member
 
Join Date: 2007-06-04
Posts: 1,062
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Cannot route between internal interfaces

Firstly do you have a route on the cluster that tells it that the 172.16.10.x sits behind the 172.16.6.1 Router.

Secondly does the 172.16.10.x network route traffic upto the R65 cluster by default or does the 172.16.6.1 router need to be told that the new network is behind the R65 cluster.

Lastly does the security policy allow this traffic to take place.
Reply With Quote
  #3 (permalink)  
Old 2007-10-24
Junior Member
 
Join Date: 2006-11-08
Posts: 19
Rep Power: 0
geelkabouter has an average reputation (10+)
Default Re: Cannot route between internal interfaces

Policy shows traffic is going through,there is a route on the firewall saying that the 172.16.10.x sits behind the router,from the 172.16.10.x the can ping and trace to the 192.168.213.x range but I cannot do it the otherway around,if I trace from the 192.168.213.x range is the get firewall interface on that range then it times out,but the smartview tracker shows traffic is allowed
Reply With Quote
  #4 (permalink)  
Old 2008-01-10
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 151
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: Cannot route between internal interfaces

Hi

Use fw montor to check if the intended traffic is appearing on the participating interfaces.

fw monitor -m iO -e "accept src=a.b.c.d or dst=a.b.c.d;"

a.b.c.d ---> destination IP
Ctrl + C to come out.
Reply With Quote
  #5 (permalink)  
Old 2008-01-11
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Cannot route between internal interfaces

My guess is NAT, maybe you are Natting 192.168.x.x and then the reply fails to come back, make sure you check the Xlated Src and Xlated Dst on the logs.

Another possibility is routing. I would double check that 172.16.10.x will route traffic back to 192.168.x.x via the said router, 172.16.6.1.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 04:00.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0