Solved

Two external interfaces with UTM-1 NGX R65

Posted on 2011-02-15
1
1,223 Views
Last Modified: 2013-11-16
I have two Checkpoint UTM-1 270s running NGX R65 in a HA cluster.  I have the several VLAN interfaces on the external interface and one non-VLAN (our default route ISP).  Routing to and from the private VLANs works fine, but I have just connected a new ISP via a VLAN on the external interface.  The connection from the ISP is up and I can PING the interface and it's gateway from the appliance, but all incoming traffic, from the internet, is dropped due to 'Address spoofing'.  I have created an object for the interface and put in a rule to allow incoming ICMP traffic, but the firewall still drops it due to spoofing.

I understand why this is happening, as the checkpoint is only expecting internet traffic to come from the interface with the default route.  But, I need the new ISP connection to allow incoming traffic, as it will be NATting traffic to a web site and other services.   Since I can't add the entire Internet to the topology of the this interface, I am at a loss here.  How do I make this happen?

This interface does not need to allow internally initiated outbound traffic (but that would be nice too.)

David Griswold

0
Comment
Question by:david_griswold
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 

Accepted Solution

by:
david_griswold earned 0 total points
ID: 34901430
Never mind.  I forgot to specify in the firewall Topology that this was an external interface.  I assumed, incorrectly, that if I associated the VLAN with the external interface when I created it, it would default to being external.  Guess not.
0

Featured Post

Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question