Solved

WatchGuard Firebox 700 reconfig error

Posted on 2003-11-24
3
497 Views
Last Modified: 2013-11-16
Hi all...

I have a problem in reconfig my watchguard firebox. once I submit the config to firebix, below error message appear..

- default route indentical to external ip
- Address * appears both as a network and interface address
- invalid default route : not on external net

pls advise, thanks...
applecow

mycase:
Internet 203.194.128.xxx ZyXEL modem(192.168.1.1)
ZyXEL Modem connected to Firebox 700 external
Firebox 700 connected to switch
switch connected to server(192.168.1.10) and client station




0
Comment
Question by:cowapple
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 33

Accepted Solution

by:
MikeKane earned 125 total points
ID: 9818853
On your Firewall, you have specified the default Gateway as the same Address you specified for the external interface.   They cannot be the same.  

Plus, from your definition, it seems that you have the same subnet defined for the internal and external nets.  

Internet 203.194.128.xxx
|
(External IF)
ZyXel External Modem
(Internal IF 192.168.1.1)
|
(External IF)
Firebox 700
(Internal IF)
|
Switch
|
Server 192.168.1.10


If you look, you have the same subnet (unless you are subnetting but I doubt that) on the outside of your firewall as you have on the inside of your firewall.  THis is a no-no.  

Try assigning as follows
Internet 203.194.128.xxx
|
(External IF)
ZyXel External Modem
(Internal IF 192.168.1.1)
|
(External IF) 192.168.1.2 SM: 255.255.255.0 GW: 192.168.1.1
Firebox 700
(Internal IF) 192.168.2.1 SM: 255.255.255.0
|
Switch
|
Server 192.168.2.10 SM: 255.255.255.0 GW 192.168.2.1

Good luck
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 10976337
No comment has been added to this question in more than 21 days, so it is now classified as abandoned..
I will leave the following recommendation for this question in the Cleanup topic area:

--> Accept: MikeKane

Any objections should be posted here in the next 4 days. After that time, the question will be closed.

tim_holman
EE Cleanup Volunteer
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question