Re: 2nd DHCP Scope?



I know when I go into the configuration of the firewall, there is a tab
called router. There is a static route in there for the 172.20.5.x network.

For the other networks 172.20.8.x, .7.x, .4.x, there are policies under the
firewall tab. Of course the 7 and 8 network are connected via the IPSEC
tunel.

Since I'm adding the 9.x network "on top" of the .4.x network and the
firewall only has an ip on the lan side for the 4.x network, I wonder if I
need to add another ip for the 9.x network. I know that the firewall can
also act as a layer 3 router if adding virutal lans to it. I do have a call
into the manufacturer to see what they say.

I would think that adding an ip range would not be this difficult. It is
the first time I'm trying it. :)



"Ace Fekay [MVP]"
<PleaseSubstituteMyActualFirstName&LastNameHere@xxxxxxxxxxx> wrote in
message news:OamOjauCGHA.3876@xxxxxxxxxxxxxxxxxxxxxxx
> In news:%23MHDCuqCGHA.412@xxxxxxxxxxxxxxxxxxxx,
> Stranger <strangerx@xxxxxxxx> stated, which I commented on below:
>> I see what you are saying. I removed the static route in the
>> firewall and then tried the tracert. It goes to the router
>> (172.20.4.1) then to the firewall (172.20.4.2) this part looks ok,
>> then it goes out to the internet. So, I think I need to somehow tell
>> the firewall that the 172.20.9.x is an internal range. Not sure how
>> to do that one if that is what it is. It was easy to do this with
>> the other IP ranges since they were coming from other buildings.
>
> The firewall appears to be a bridge, and not a router in your scenario
> beacuse it has a 4 interface as well as the "gateway". Is that
> intentional?? I'm totally confused. Your drawing is confusing.
>
> If the firewall is just bridged, then nothing needs to be done, however,
> if it were not bridged, and it has a different IP, then the static rules
> apply to it just as if it were a regular old non-firewall router. Follow
> my example, in this case the firewall would be like Router A, where as the
> "router" is Router B.
>
> Internal net --- Router --- Firewall -- Internet
>
> Internal net is 172.20.9.0, where these machines are sitting on
> 172.20.4.0.
> "Router" above would need nothing sine I am assuming the one of it's
> interfaces is on the 172.20.9.0 side, and the other interface would be on
> the 172.20.4.0 side, but the firewall is.
>
> Ace
>


.



Relevant Pages

  • Re: Host Computer with ICS cannot be accessed
    ... You read my mind on the router thing. ... My home network is a piece of cake... ... >>firewall settings, not that I've found so far, but I'll keep looking. ... and we couldn't get file sharing working until ...
    (microsoft.public.windowsxp.network_web)
  • Re: share my printer between 2 computers and surf with 2 computers at same time
    ... The main choice you have to make is whether to have the router include wireless capability or not. ... Because wireless routers for home use are relatively inexpensive these days, I'd suggest buying a wireless router even if you don't initially intend to use that capability. ... If you already have a UTP cable going between upstairs and downstairs, you can use that to have a wired network. ... caused by 1) a misconfigured firewall; ...
    (microsoft.public.windowsxp.network_web)
  • Re: share my printer between 2 computers and surf with 2 computers at same time
    ... The main piece of hardware you need to buy is a router. ... Because wireless routers for home use are ... you can use that to have a wired network. ... caused by 1) a misconfigured firewall; ...
    (microsoft.public.windowsxp.network_web)
  • RE: [Full-Disclosure] Re: January 15 is Personal Firewall Day, help the cause
    ... the>outside world which are in response to packets originating from ... to drop in a little Trojan, your whole network can be compromised. ... NAT router works at Layer 3. ... You still need a personal firewall or ...
    (Full-Disclosure)
  • Re: MSN WORKGROUP
    ... before my router is excess the folder very quickly suddenly it excess the ... Pls guide me how can i make it again this network. ... xp or firewall., secondly i can not find my wirefall optopn in control panel ... Problems sharing files between computers on a network are generally ...
    (microsoft.public.windowsxp.network_web)

Loading