Firewall-1

Re: [FW-1] Automatic ARP not working

Subject: Re: [FW-1] Automatic ARP not working
From: Alb <albllovet AT E-MILIO DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Mon, 24 May 2004 17:51:46 +0200
Hi!

I've NG FP3 HF-2 on solaris boxes (fw ctl arp is just for win32
enviroment) , and I've tried old style way, without using automatic arp
and using local.arp files properly. But it still doesn't work.

Regards

Oswaldo Silva Junior wrote:

Hi Alb,

I don't know if you still having problems with this...

Do you have any hotfix installed? I have the same environment here and 
experienced the same behaviour in NG FP3. I executed 'fw ctl arp', the arp list 
appeared but without responses. To correct this I installed, on that time, NG 
FP3 HF-2. Today I have hotfix HFA-325 installed.

Regards

Dig.

-----Original Message-----
From: Alb [mailto:albllovet AT E-MILIO DOT COM]
Sent: quarta-feira, 19 de maio de 2004 06:31
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Subject: [FW-1] Automatic ARP not working


Hi!

I'm using Cluster XL with HA 'new mode' configuration, NG FP3. I've
several hosts with automatic nat. I've checked the Automatic ARP
configuration on Global Properties.

In the help:

"Automatic ARP configuration  - ARP tables on the VPN/FireWall Module
machine (gateway) performing NAT will be automatically configured so
that ARP requests for a translated (NATed) machine, network or address
range are answered by the gateway."

"This option removes the requirement (present in VPN-1/FireWall-1 prior
to Version NG) for manual ARP configuration (using the arp command in
Unix or the local.arp file in NT)."


The problem is that I see arp request, asking the mac of the virtual
address, on the firewall nic, but it does not respond.

Any idea?

thanks.

Alb




=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>