Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Firewall-1, Static Address Translation problem
From: ping <ping @ tm . net . my>
Date: Wed, 30 Jul 1997 20:38:10 -0700
To: Patrik Backstrom <pb @ techno . org>
Cc: firewalls @ greatcircle . com
References: <Pine . LNX . 3 . 95 . 970730122546 . 9B-100000 @ warp . techno . org>
Reply-to: ping @ tm . net . my

Patrik Backstrom wrote:
> 
> Hi!
> 
> I have a problem with static address translation. When the client on the
> inside connects to the outside, everything works fine. But when a machine
> on the outside tries to connect to the client's valid ip, it just won't go
> trough the firewall.
> 
> I have configured the Network Object, Workstation, Address Translation for
> Automatic Rules, Static and the Valid IP adress.
> 
> The logs on the Firewall-1 says that the packet is accepted, but it won't
> reach the internal client.
> 
> It can't be a routing problem, since it works fine when the client
> connects to the outside world. The source IP after the translation is also
> correct.

Did you put a static route saying from that private static IP 
going to your internal gateway?  And try to do a static arp
for that privat static IP with arp -s.  If you didn't, your 
firewall is just keep on arp'ing.......

> 
> /pb
> 
>  ---------------------------------------------------------------------
>   Patrik Bäckström (BOFH)   Phone........: +46-(0)706-661928
>   Hjalmar Bergmans gata 50  Homepage.....: http://warp.techno.org/
>   422 52 Hisings Backa      E-Mail.......: pb @
 techno .
 org
> 
>   PGP Pub Key......: http://warp.techno.org/~pb/pgpkey
>              \.....: finger pb @
 warp .
 techno .
 org
>  ---------------------------------------------------------------------

Best Regards,
Cheng Ping Onn.


References:
Indexed By Date Previous: Java Applet Scanner
From: "Jerry Edmiston" <jle9 @ eci-esyst . com>
Next: Re: Re: Virus Scanner
From: Rick Murphy <rick @ tis . com>
Indexed By Thread Previous: Firewall-1, Static Address Translation problem
From: Patrik Backstrom <pb @ techno . org>
Next: Lotus Notes Servers
From: "Jerry Edmiston" <jle9 @ eci-esyst . com>

Google
 
Search Internet Search www.greatcircle.com