Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Mixture of PIX and Checkpoint firewall

Dear ALL,

I have a PIX 515 F/W with one interface connected to the Internet and other to the inside network( are working fine.

Now I want to put a Database server which would be on a different network ( and would be protected by a checkpoint firewall.

I have configured the checkpoint firewall on NT 4 with 2 interface one connected to our internal network( and one to network with the database server( have setup the policy on the checkpoint firewall .The segment users are able to acces the dbase server in segment.

I want people from the internet to cnnectto the DB server .Can anyone explain what needs to be done the PIX 515 and the checkpoint to get this going.



New Member

Re: Mixture of PIX and Checkpoint firewall

You have to setup the following on the PIX firewall:

- Setup a static route for the network pointing to the CP firewall.

- Setup a static translation

- Modify your inbound access list to allow traffic to the DB server

New Member

Re: Mixture of PIX and Checkpoint firewall

Thank you very much .It worked by doing what you said.

now the Routing table is as follows in my pix:

outside x.x.x.x 2 OTHER static

inside 1 OTHER static

inside 1 CONNECT static

inside 1 OTHER static

outside x.x.x.x 255.255.255.x x.x.x.x 1 CONNECT static

I had to add "inside 1 OTHER static " to get the routing to work properly, though I fail to understand why this line is required.

Below is the interface details of PIX and checkpoint FW.

Also The users in the segment are not able to speak to segment until I put a static route to segment in each PC ,this despite the fact that the PIX has a static entry to segment and the default g/w of all the nodes in segment is pix inside interace ie this exlain this as well.

pix inside=

PIx outisde=213.x.x.x x.x.x.x

checkpoint outside=

checkpoint inside=

Hope I have explained my problem properly which would be understood by someone I guess.

Thks again

CreatePlease login to create content