Firewall-1

[FW-1] NG AI VRRP Anti-Spoofing

Subject: [FW-1] NG AI VRRP Anti-Spoofing
From: David Beattie <DavidB AT EURODATASYSTEMS DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Fri, 25 Jul 2003 12:41:36 +0100
Dear All,

I am trying to get a pair of Nokia IP440's up and running as a VRRP pair 
running Firewall-1 NG-AI. This is a very simple scenario with two 4-port NICs 
in each, No NAT, No VPNs, No SecuRemote/Client.

All looks fine until I try to put Anti-Spoofing on, then it complains that some 
of the VRRP packets are coming in from the wrong interface intermittently. When 
running traffic across the system it also shows traffic intermittently coming 
into the wrong interface. It even continues to report Anti-Spoofing events when 
I turn all anti-spoofing checks off.

When I run the primary firewall by itself, everything behaves properly, but 
everything seems to grind to a halt when I start the second firewall.

Has anyone heard of IPSO 3.7 or NG-AI behaving like this, or have any ideas 
about how to troubleshoot it?

Thanks

Dave Beattie

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>