Unsolved

This post is more than 5 years old

2 Posts

10544

November 19th, 2004 14:00

6024 routing to Watchguard FB 1000

We have setup a 6024 with a number of VLANs which are all routing fine between other switches on the VLANs.
 
We are now trying to connect the optional and trusted networks on the FB to the 6024.
 
We have tried setting up port g1 to ip 192.168.229.1 255.255.255.0 for the trusted network with the trusted network IP on the firebox being 192.168.229.254 and then connecting it to port g1.
 
We have then tried setting up port g23 to ip 192.168.230.1 255.255.255.0 for the optional network with the optional network IP on the firebox being 192.168.230.254 and then connect it to port g23.
 
From the router we can ping both 192.168.229.254 & 192.168.230.254.  However when trying to ping from any other VLAN (see below for details) we get a request timed out.  If we unplug either the optional of the trusted or even both the ping reply comes back with destination network unreachable.
 
Granted this implies the issue is with the firebox but we cannot find out where.  So any help will be greatly appreciated.
 
VLAN 1 is set to IP 192.168.228.1 255.255.255.0
VLAN 101 is set tp IP 192.168.221.254 255.255.255.0 & 192.168.220.254 255.255.255.0
VLAN 103 is set to IP 192.168.222.254 255.255.255.0
 
At this moment in time all we want to get happening is that any IP on any VLAN can ping the firebox on either external or internal.  The firebox does not have any policies applied, it does from what we can see think that the pings are coming from spoofed IP addresses which is where we think the problem lies.  So I guess what we are asking is for advice and what the routes should be like on the Firebox or what we could set as route on the 6024
 

2 Posts

November 22nd, 2004 13:00

Yep thanks we finally worked it out, we had mis understood the gateway option on the firebox

2 Intern

 • 

812 Posts

November 22nd, 2004 13:00

It sounds like the firewall does not have a route back to the network on the 6024. If the firewall does not have an interface on that network, it does not know where to send traffic to the destination. You should be able to either configure a default route or static routes on the firewall pointing back to the IP interface on the 6024.
No Events found!

Top