Re: [fw-wiz] Remote Access via Checkpoint VPN

From: Devdas Bhagat (devdas_at_dvb.homelinux.org)
Date: 08/22/04

  • Next message: Paul D. Robertson: "RE: [fw-wiz] Top Secret DOD Data over the Public Internet? Thoughts?"
    To: firewall-wizards@honor.icsalabs.com
    Date: Sun, 22 Aug 2004 19:41:47 +0530
    
    

    On 18/08/04 10:57 -0400, Desai, Ashish wrote:
    > > -----Original Message-----
    > > From: Ludolph, Michel [mailto:Michel.Ludolph@atosorigin.com]
    > > Sent: Tuesday, August 17, 2004 4:52 AM
    > > To: firewall-wizards@honor.icsalabs.com
    > > Subject: [fw-wiz] Remote Access via Checkpoint VPN
    > > Internet------10.x.x.x--FW--10.x.x.x----- Internal network
    > > |
    > > |
    > > |
    > > 20.20.20.20 (DMZ)
    >

    Quoting fixed. Mr Desai might want to learn to quote messages and stop
    posting first.

    > You might want to read this BEFORE you try anything this X!@#$!#$
    As I understood the diagram above,
     
    Internet (ISP router) ---- public address of router
                                    |
                                    RFC 1918 space
                                    |---- firewall--- LAN in RFC1918 space
                                            |
                                            |
                                    DMZ with public IP space

    Given that a lot of ISPs will use RFC 1918 address space for point to
    point links (they shouldn't, but they do), it might be perfectly
    possible for the ISP to be NATing the addresses and routing the public
    IP space. Also, given a very small public address space, there may not
    be the option of subnetting it and extracting a /30 from it for the
    firewall external interface.

    As the OP said,
    > > the problem, my FW-external interface has a private IP-address, which is
    > > not routable via the Internet. In order to make this working I would
    > > like the VPN to bind to the DMZ-interface (20.20.20.20) instead of the
    > > external interface.
    he clearly understands that RFC 1918 space is not routed via the
    Internet. That the firewall has an external interface with a RFC 1918
    addresses is a totally different issue than routing it via the internet

    Devdas Bhagat
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul D. Robertson: "RE: [fw-wiz] Top Secret DOD Data over the Public Internet? Thoughts?"

    Relevant Pages

    • Re: [SLE] samba and firewall issue
      ... the internet (your router/gateway/dsl-modem... ... >>Have you configured that firewall no firewall comes preconfigured (I ... >>make sure you have tight firewall rules applied on your border router. ... > it) I wonder which is my external interface then and which my internal one. ...
      (SuSE)
    • RE: Firewall Question
      ... You might want to consider subscribing to the Firewall mailing list. ... besides opening port 80 at the access list from internal ... do I need to open the port 80 from external interface? ... In the case of Cisco router, what should I do in order to allow Internet ...
      (Security-Basics)
    • Re: ipfw rules
      ... > send packets trough external interface rl0. ... > but cannot send any packets out from my lan box. ... I can connect to internet ... They should look like packets originating on the firewall if natd is ...
      (comp.unix.bsd.freebsd.misc)
    • Re: Back to Back ISA Servers
      ... I want the remote users to access the internet through our internet isa ... "Phillip Windell" wrote: ... >> external interface. ... >> firewall. ...
      (microsoft.public.isa)
    • Re: avast
      ... > Just did a clean installation of xp pro sp1 and download 'avast anti ... Did you firewall before connecting to the internet? ... Internet and patch with the critical updates? ... Why you should use a computer firewall.. ...
      (microsoft.public.windowsxp.general)