Re: adding new ip range to fw-1
From: Michael Pelletier (mjpelletier_at_mjpelletier.com)
Date: Sat, 26 Mar 2005 00:47:20 -0800
Joey D wrote:
> We have just been given an additional ip address range from our ISP
> due to reaching capacity on our existing range.
> Having just assigned one of these new ip addresses to an internal host
> I am unable to connect from the outside world. If I assign one of the
> existing ip addresses to the host I can connect with no problems.
> Do I have to configure something in FW-1 to get it to recognise and
> accept packets destined for this new network?
ah...ya! Remember you are ADDING another subnet. You MUST cofigure your
equipment, firewalls rules and routing to accomplish this....
> The new range is of the same class but a different sub network. I have
> attempted to add the range to the FW cluster object in the topology
> and also assigned an ip address to the nokia ip380 ipso 3.8.
No idea what your are talking about. Sounds like you added the subnet to the
firewall? How? Did you add the subnet to a new DMZ interface? Did you try
to supernet the subnets together (contigous range?). Please specify. DOn't
forget you also have to modify your firewall rules too!
> ... but no luck as yet trying to establish an external connection.
> When I try to tracert to one of the new addresses it seems to stop
> short at a router in the ISP. Perhaps they haven't configured the new
> range to route through our existing router(?).
It is posible or you have not configured your routing or firewall rules
correctly. I really need more information...
> Can someone kindly guide me please?
Send more information....
> Many thanks,