Firewall Wizards mailing list archives

RE: FW1 on NT and setting the external interface


From: "Joe Ippolito" <joe () joesnet com>
Date: Thu, 19 Aug 1999 23:41:53 -0700

You will have to take the mutiple external interface issue up with Check
Point.  I don't believe it will consider more than one as external.  As for
the concurrent sessions - I don't believe this is true.  I have seen it log
anything going by an internal interface even if it did not go through the
firewall.  I believe it puts the interfaces in promiscuous mode and
remembers any address it can pick up - broadcasts give them away every time.
The only way I have seen to circumvent their license checker is to isolate
it with another firewall, proxy or router with access lists.  But, what's
the point in having it then?  I guess Check Point does not trust anybody,
not even their customers.  But then if they were like MS, they probably
would not have any competition.

-----Original Message-----
From: owner-firewall-wizards () lists nfr net
[mailto:owner-firewall-wizards () lists nfr net]On Behalf Of Alex Ho
Sent: Wednesday, August 18, 1999 6:54 AM
To: Thomas Crowe
Cc: Firewall-Wizards@Nfr. Net
Subject: Re: FW1 on NT and setting the external interface


Hi

On Tue, 17 Aug 1999, Thomas Crowe wrote:
interface set. However when I create and edit the external.if in
$FWDIR/conf
I still get the same problem.  I have tried all of the following formats
for
naming the interface:  The NT name (Cpqnet01), the FW bound name
(FW-Cpqnet01), the name assigned to it in the gateway properties
(External),
I believe I even tried the IP address. All to no avail.  Another part of

On the Windows NT command prompt, type "ipconfig"
It will say Ethernet Adapter XXX, where XXX is the interface name.


this is that I ma protecting my internal LAN from multiple external
wans/lans so how do I also assign multiple external interfaces in the
external.if


FW-1 license is based on the number of concurrent assesses, so it doesnt
matter if your internal number of accesses is less than the license
allowed.


Regards
Alex

INFINITUM Singapore Pte Ltd
alex () infinitum com            > http://www.infinitum.com
singapore > voice 65-3236360  > fax  65-3236390



Current thread: