Re: Symantec 5620 : permit traffic entering and exiting the same interface

Re: Symantec 5620 : permit traffic entering and exiting the same interface

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Re: Symantec 5620 : permit traffic entering and exiting the same interface Wayne 03-05-2007
Posted by Wayne on March 5, 2007, 9:55 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> Hi friends,
>
> I just had a basic question on configuring Symantec 5620 firewall. I
> wanted to know what is the equivalent of Cisco command same-security-
> traffic permit intra-interface in Symantec firewall.
>
> The reason that I am asking is because the Symantec firewall is the
> default gateway of a LAN 192.168.0.0/24. Now, the firewall has a
> static route to reach 192.168.1.0 segment.
>
> So, other computers / servers whose default gateway is Symantec
> firewall will also talk to the 192.168.1.0 network through the
> Symantec firewall's static route to 192.168.1.0 network. Right now,
> they are not able to talk to 192.168.1.0 network unless i create a
> static route on the specific PC's / servers.
>
> Now how can I avoid adding static routes on the individual PC's /
> servers ? There should be a feature to allow the firewall to pass
> traffic entering and exiting the same firewall's interface. The
> packets are entering the firewall's inside interface and leaving the
> firewall's inside interface. They are not touching the firewall
> interface's public or outside interface.
>
> Please advise.
>
> Thanks a lot
> Gautam
>

This will work, but in addition to adding the static route, you will need to
create a rule that will allow traffic FROM 192.168.0.0 /24 TO 192.168.1.0
/24 and selecting the protocol group (possibly "all" protocols).



Similar ThreadsPosted
Permit web traffic by user March 14, 2006, 4:03 am
Allow printing traffic from DMZ(Lower Security interface) to inside network on PIX 515E December 8, 2005, 2:53 pm
Netscreen - Dual-Untrust configuration - need to route email traffic out specific interface October 5, 2006, 9:37 pm
Norton: "Permit All" doesn't October 13, 2005, 1:27 pm
bootpc incoming UDP permit? July 2, 2005, 9:37 pm
Norton firewall won't permit Eudora access December 22, 2004, 12:16 am
Symantec VPN client for a MAC (v8 or v9)/ Symantec VPN CLient for Vista x64 yet/connection issues.. April 30, 2007, 9:45 am
Re: FTP outward traffic causing "Unidentified IP traffic" error on ISA 2004 server connected to a PIX May 31, 2006, 8:57 am
Pulling down the red interface May 8, 2005, 8:07 pm
Citrix web Interface December 1, 2005, 5:18 pm

The site map in XML format XML site map

Contact Us | Privacy Policy