nauman_ahmed
asked on
Netscreen 5GT Firewall Setup with Class C IP Block
I have a netscreen 5GT firewall and a class C IP block. I would like to create three sub net in the firewall:
First Subnet: 192.168.0.1-192.168.0.100
Second Subnet: 192.168.0.101-192.168.0.25 4
Third Subnet: 192.168.1.1-192.168.1.254
Can this be done in Transparent mode? Do I have to configure NAT mode in the firwall? I really appreciate your help.
Thanks.
First Subnet: 192.168.0.1-192.168.0.100
Second Subnet: 192.168.0.101-192.168.0.25
Third Subnet: 192.168.1.1-192.168.1.254
Can this be done in Transparent mode? Do I have to configure NAT mode in the firwall? I really appreciate your help.
Thanks.
The best you could do with the the first and second is split it in two with a 255.255.255.128 mask and use 192.168.0.1-126 and 192.168.0.129-254. However you could use 3 networks with 24 bit masks like 192.168.0.0, 192.168.1.0, and 192.168.2.0.
I'm not sure you can do this in transparent mode on the 5gt. You may have to create subinterfaces to handle your multiple subnets. If you Need physical seperation by port. You can use home/work mode in combination with a subinterface.
The whole point of transparent mode is to avoid L3, isn't it? So I guess you're trying to do something which is not clear to us. Can you be a bit more specific on why you want to do this or what you're trying to do?
Cheers,
rsivanandan
Cheers,
rsivanandan
ASKER
Thanks for the reply guys, it was very helpful. I hope the following make it clear on what I am trying to do:
I have a class C IP address and I would like to configure the Netscreen 5GT firewall for the following environments:
1. Office - 128 IPs
2. Development Environment - 128 IPs
3. Production Environment - 256 IPs
I am trying to accomplish the above using one firewall. Would it be possible with or without NAT?
Thanks.
I have a class C IP address and I would like to configure the Netscreen 5GT firewall for the following environments:
1. Office - 128 IPs
2. Development Environment - 128 IPs
3. Production Environment - 256 IPs
I am trying to accomplish the above using one firewall. Would it be possible with or without NAT?
Thanks.
ASKER
Rick_O_Shay:
If I have to split it the way you mentioned, what needs to be defined in firewall network settings?
Thanks.
If I have to split it the way you mentioned, what needs to be defined in firewall network settings?
Thanks.
If you either subnet the one network or use 3 separate networks you need to have a router interface with a respective IP address in each one. So in the subnet case it could 192.168.0.1/25 and 192.168.0.129/25 for your router interface addresses.
When the firewall is in transparent mode, you only have L3 info for accessing the firewall. So in your case, you want to have 3 networks as you mentioned. what should be done is to have this setup in your lan and send it across firewall (You don't do anything on the firewall). The routing between these networks should be taken care by a router and not this firewall. Something like this;
Office-------------------
|
Dev Env----------------
|-----Internal Router---------Firewall in transparent Mode---------Internet
Prod Env---------------
|
If you can't do that, like you want to have this done by the firewall then you'd have to move the firewall away from transparent mode.
Cheers,
rsivanandan
Office-------------------
|
Dev Env----------------
|-----Internal Router---------Firewall in transparent Mode---------Internet
Prod Env---------------
|
If you can't do that, like you want to have this done by the firewall then you'd have to move the firewall away from transparent mode.
Cheers,
rsivanandan
ASKER
Thanks rsivanandan:
What needs to be done if I move the firewall from transparent mode? What configuration change will be required in firewall?
Thanks.
What needs to be done if I move the firewall from transparent mode? What configuration change will be required in firewall?
Thanks.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.