Link to home
Start Free TrialLog in
Avatar of PeraHoman
PeraHoman

asked on

Firewall question

We use FireMON(pretty much a firewall policy ticket application) where I work.  

Remote site network: 10.0.1.0/24
PER/CER: 172.16.1.0/30

If I've submitted a ticket to allow 10.0.1.0/24, but didn't for 172.16.1.0/30, am I going to have FW issues?  Let's say the /24 covers everything I need at this remote site (workstations, core-router /30, L0), its just 172.16.1.0/30 that doesn't have routes/rules.

We use checkpoint.
SOLUTION
Avatar of noci
noci

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of PeraHoman
PeraHoman

ASKER

I guess my question is, is it typical to create FW rules for /30 links or is it not necessary since the source IP will be from /24 subnet?  Has anyone experienced issues where there weren't rules in place for their PER/CER subnet?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
how about is there any scenario anyone can think of that needs the per/cer p2p /30  through a firewall?
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial