as the APs seem to connect to the ASG via the 1.2.3.4 pseudo IP address: is it possible to DNAT this IP to the v7 ASG from a different network, in order to use the ASG as e.g. a WiFi controller in a DMZ?
I can't see any reason why this shouldn't work, although I also can't see any reason why anyone would want to do this (except for reluctance to downgrade the "main" firewall to version 7 to test wireless). Just try it and tell us the results [:)]
Since this is not really a supported setup you would need to manually adjust this ruleset to keep it working if we ever change this magic IP. Cheers, Andreas
I can't see any reason why this shouldn't work, although I also can't see any reason why anyone would want to do this (except for reluctance to downgrade the "main" firewall to version 7 to test wireless). Just try it and tell us the results [:)]
Since this is not really a supported setup you would need to manually adjust this ruleset to keep it working if we ever change this magic IP. Cheers, Andreas