- Posts: 3
- Thank you received: 0
Netasq f50 firewall, cannot ping to other segment...
17 years 6 months ago #21815
by ntxploits
Netasq f50 firewall, cannot ping to other segment... was created by ntxploits
There is some problem while configuring this firewall. Here is the lab environment for this firewall.
For dmz pc, I’m using ip addr 10.0.0.21, gw is 10.0.0.1 (this is dmz segment)
N for internal network, I’m using ip 172.168.0.21 for testing n 172.168.0.3 for gateway…
172.168.0.21
172.168.0.3--- 10.0.0.1
10.0.0.21
Internal pc fw internal fw dmz dmz pc
The problem is I cannot ping from dmz pc to internal pc
here is the syslog from the fw that shows it already pass the fw...
ruleid=1 srcif="Ethernet2" srcifname="dmz" ipproto=icmp icmptype=8 icmpcode=0 proto=icmp src=10.0.0.21 srcname=dmzpc dst=172.168.0.21 action=pass logtype="filter"
but how come result from the ping shows time out…
there’s no personal firewall inside the testing machine.
For dmz pc, I’m using ip addr 10.0.0.21, gw is 10.0.0.1 (this is dmz segment)
N for internal network, I’m using ip 172.168.0.21 for testing n 172.168.0.3 for gateway…
172.168.0.21
172.168.0.3--- 10.0.0.1
10.0.0.21
Internal pc fw internal fw dmz dmz pc
The problem is I cannot ping from dmz pc to internal pc
here is the syslog from the fw that shows it already pass the fw...
ruleid=1 srcif="Ethernet2" srcifname="dmz" ipproto=icmp icmptype=8 icmpcode=0 proto=icmp src=10.0.0.21 srcname=dmzpc dst=172.168.0.21 action=pass logtype="filter"
but how come result from the ping shows time out…
there’s no personal firewall inside the testing machine.
Time to create page: 0.107 seconds