Firewall-1

Re: [FW-1] NG AI VRRP Anti-Spoofing

Subject: Re: [FW-1] NG AI VRRP Anti-Spoofing
From: David Beattie <DavidB AT EURODATASYSTEMS DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Tue, 29 Jul 2003 09:38:11 +0100
Thanks for the info. I have come across another VRRP issue with IPSO 3.7. If I 
define a VRRP interface as:

fwA 1.1.1.1/24
fwB 1.1.1.2/24
VIP 1.1.1.3/24

and then realise that I have used 1.1.1.1/24 elsewhere, so I want to shift all 
of the IPs up one:

fwA 1.1.1.2/24
fwB 1.1.1.3/24
VIP 1.1.1.4/24

fwB complains that VIP 1.1.1.3/24 conflicts with interface 1.1.1.3/24, even 
though I am not asking it to use VIP 1.1.1.3/24 anymore and I can't find a way 
around it. I am considering erasing the entire VRRP set up (eight 
interfaces)and set it up using "legacy VRRP".

Regards,

Dave Beattie

-----Original Message-----

I have similar issues on an IP380 with NG FP3.  The solution, so far, is
to use NG FP3 HFA314 with VRRP monitored circuits.  VRRP v2 does not work
and we currently have a case open with Checkpoint and Nokia to get this
resolved.

Regards,
Alex Chircop

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>