Hi,
We recently tried to upgrade our ASL5 firewall to ASL7 but didn't quite make it.
ASL7 was installed from scratch to a identical box as the ASL5 and all of the configurations were copied by hand and at least triple-checked.
The firewall interface and network configuration is IMO very basic one:
ISP Cisco
|
eth1
|
ASL - eth2 - LAN (private IPs)
|
+--- eth3 - DMZ (public IPs)
Everything else is working ok, but hosts in the DMZ network are unable to access the internet. Actually the traffic stops at the ASL, since the hosts are unable to even ping the router. The eth3 interface has a private IP assigned to it and traffic to the DMZ hosts has been statically routed.
So far we have tried booting everything (Cisco, hosts, switches..), Proxy ARP for DMZ and External interfaces and waiting for several hours in case some miserable ARP table somewhere refuses to update itself.
And still, this exact same configuration works like a charm in the ASL5 box.
This thread was automatically locked due to age.