adding new ip range to fw-1

adding new ip range to fw-1

Secure Home | Search | About

Networking Firewalls - Software and hardware firewalls discussions 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
adding new ip range to fw-1 Joey D 03-24-2005
Posted by Joey D on March 24, 2005, 4:18 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

We have just been given an additional ip address range from our ISP
due to reaching capacity on our existing range.
Having just assigned one of these new ip addresses to an internal host
I am unable to connect from the outside world. If I assign one of the
existing ip addresses to the host I can connect with no problems.

Do I have to configure something in FW-1 to get it to recognise and
accept packets destined for this new network?

The new range is of the same class but a different sub network. I have
attempted to add the range to the FW cluster object in the topology
and also assigned an ip address to the nokia ip380 ipso 3.8.

.... but no luck as yet trying to establish an external connection.

When I try to tracert to one of the new addresses it seems to stop
short at a router in the ISP. Perhaps they haven't configured the new
range to route through our existing router(?).

Can someone kindly guide me please?

Many thanks,

Joe


Posted by Michael Pelletier on March 26, 2005, 12:47 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Joey D wrote:

> Hi,
>
> We have just been given an additional ip address range from our ISP
> due to reaching capacity on our existing range.
> Having just assigned one of these new ip addresses to an internal host
> I am unable to connect from the outside world. If I assign one of the
> existing ip addresses to the host I can connect with no problems.
>
> Do I have to configure something in FW-1 to get it to recognise and
> accept packets destined for this new network?

ah...ya! Remember you are ADDING another subnet. You MUST cofigure your
equipment, firewalls rules and routing to accomplish this....

> The new range is of the same class but a different sub network. I have
> attempted to add the range to the FW cluster object in the topology
> and also assigned an ip address to the nokia ip380 ipso 3.8.

No idea what your are talking about. Sounds like you added the subnet to the
firewall? How? Did you add the subnet to a new DMZ interface? Did you try
to supernet the subnets together (contigous range?). Please specify. DOn't
forget you also have to modify your firewall rules too!


> ... but no luck as yet trying to establish an external connection.
>
> When I try to tracert to one of the new addresses it seems to stop
> short at a router in the ISP. Perhaps they haven't configured the new
> range to route through our existing router(?).

It is posible or you have not configured your routing or firewall rules
correctly. I really need more information...

> Can someone kindly guide me please?

Send more information....

> Many thanks,
>
> Joe

Michael

--
news.west.cox.net


Posted by Joey D on March 31, 2005, 3:15 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi - thanks for your reply. Please see my comments below...
Joe

> Joey D wrote:
>
> > Hi,
> >
> > We have just been given an additional ip address range from our ISP
> > due to reaching capacity on our existing range.
> > Having just assigned one of these new ip addresses to an internal host
> > I am unable to connect from the outside world. If I assign one of the
> > existing ip addresses to the host I can connect with no problems.
> >
> > Do I have to configure something in FW-1 to get it to recognise and
> > accept packets destined for this new network?
>
> ah...ya! Remember you are ADDING another subnet. You MUST cofigure your
> equipment, firewalls rules and routing to accomplish this....
>
-- The new range is purley so that we can map internal hosts with
external public ip addresses.

-- My first problem was that the internet facing router had not been
configured by our ISP. This has been done now and I can ping it.
My firewall is a nokia ip with ng ai r55 (dual fw in ha - vrrp). I
also manually configured both firewalls (via ipso) with the next 2 ip
addresses in the new range (the first being that of the external
router). I'm presuming this is standard practice but HAVE NOT
configured any routes - should I be?
The FWs are obviously defined as a cluster object in FW-1. I
configured each of the FW objects with a new interface in the topology
(externally facing) with their respective ip address (as defined in
ipso) - these interfaces are configured as non-clustered.
Finally I created a network object for the new range.

> > The new range is of the same class but a different sub network. I have
> > attempted to add the range to the FW cluster object in the topology
> > and also assigned an ip address to the nokia ip380 ipso 3.8.
>
> No idea what your are talking about. Sounds like you added the subnet to the
> firewall? How? Did you add the subnet to a new DMZ interface? Did you try
> to supernet the subnets together (contigous range?). Please specify. DOn't
> forget you also have to modify your firewall rules too!
>
-- The new range is not contigous with the current. I have simply
created a network object and defined it there. I can't see what other
options I have here.
>
> > ... but no luck as yet trying to establish an external connection.
> >
> > When I try to tracert to one of the new addresses it seems to stop
> > short at a router in the ISP. Perhaps they haven't configured the new
> > range to route through our existing router(?).
>
I am able to tracert to any of the new addresses now within my network
but externally everything stops at the external router interface. If I
change one of the nat rules to use an existing ip address I can get
through and it works as expected.
I've gone through every setting trying to compare the differences to
our existing range/config with the new but am having no luck!
Could it be a routing issue?

> It is posible or you have not configured your routing or firewall rules
> correctly. I really need more information...
>
> > Can someone kindly guide me please?
>
> Send more information....
>
> > Many thanks,
> >
> > Joe
>
> Michael

Many thanks for any help.

Joe


Posted by Joey D on April 1, 2005, 1:15 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Update: I've been on the phone with my isp and ran through some tests. The
router is working fine.
Therefore it is a firewall issue.

Joe


> Joey D wrote:
>
>> Hi,
>>
>> We have just been given an additional ip address range from our ISP
>> due to reaching capacity on our existing range.
>> Having just assigned one of these new ip addresses to an internal host
>> I am unable to connect from the outside world. If I assign one of the
>> existing ip addresses to the host I can connect with no problems.
>>
>> Do I have to configure something in FW-1 to get it to recognise and
>> accept packets destined for this new network?
>
> ah...ya! Remember you are ADDING another subnet. You MUST cofigure your
> equipment, firewalls rules and routing to accomplish this....
>
>> The new range is of the same class but a different sub network. I have
>> attempted to add the range to the FW cluster object in the topology
>> and also assigned an ip address to the nokia ip380 ipso 3.8.
>
> No idea what your are talking about. Sounds like you added the subnet to
> the
> firewall? How? Did you add the subnet to a new DMZ interface? Did you try
> to supernet the subnets together (contigous range?). Please specify. DOn't
> forget you also have to modify your firewall rules too!
>
>
>> ... but no luck as yet trying to establish an external connection.
>>
>> When I try to tracert to one of the new addresses it seems to stop
>> short at a router in the ISP. Perhaps they haven't configured the new
>> range to route through our existing router(?).
>
> It is posible or you have not configured your routing or firewall rules
> correctly. I really need more information...
>
>> Can someone kindly guide me please?
>
> Send more information....
>
>> Many thanks,
>>
>> Joe
>
> Michael
>
> --
> news.west.cox.net




Similar ThreadsPosted
adding IP2 to IPCOP December 11, 2006, 11:46 am
adding a network - nokia+checkpoint April 5, 2005, 1:58 pm
Kerio 2.1.5 adding posts to block "virus flood" August 17, 2005, 7:50 pm
Firewall Tests Lower after Adding DSL Modem/Router July 25, 2006, 5:20 pm
IP Spoofing In My IP Range!!! January 20, 2005, 3:53 am
new ip address range April 3, 2005, 8:22 pm
IP address range October 20, 2005, 5:58 pm
configuring IP range for zones September 19, 2007, 3:26 pm
Extending range of wireless network November 28, 2004, 8:34 pm
SuSeFirewall2 and range of addresses without using mask December 17, 2004, 10:17 am

The site map in XML format XML site map

Contact Us | Privacy Policy