OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: 1 mngmt console, 2 fw modules?
From: Jeffery.Gieserminnesotamutual.com
Date: Wed Oct 18 2000 - 08:21:23 CDT


Christian,

#Has anyone successfully managed a second firewall module from a management
#console, which is NATed behind the first firewall? Including logging?

#Example:

#console ---> firewall B (NATing) ---> Internet ---> firewall B

#Thanks for any help,

As long as the second firewall knows that the source IP address of the
management console is the firewall (and not the real IP address of the
console), it should work fine. Note: You didn't mention a specific
firewall and if your firewall management console puts it's IP address in
the packet and the remote firewall checks it against the source IP address
of the packet then it may reject it. This could possibly be considered
protection against some replay attacks.

Regards,
Jeffery Gieser

-
[To unsubscribe, send mail to majordomolists.gnac.net with
"unsubscribe firewalls" in the body of the message.]