dshf21391
Advanced Member | Редактировать | Профиль | Сообщение | Цитировать | Сообщить модератору Solution Follow these guidelines: If traffic is sent through Security Gateway between two external interfaces, then a sufficient license has to be installed. If traffic that should be forwarded to an internal interface is being forwarded out of the external interface, then add static routes to properly route the traffic. Example: There are internal subnets that are not directly connected to the Security Gateway: Net 172.16.0.0/24 --- Router --- Net 192.168.0.0/24 --- Security Gateway --- Internet The 172.16.0.0 network is configured to be part of the Anti-Spoofing configuration on the Security Gateway, but when packets from the 172.16.0.0 network are routed to the Internet, the reply packets are not properly routed from the Security Gateway to the Router and are dropped with the reason above. Clarification: Some licenses impose a limit on the number of hosts that will be protected by the Security Gateway (e.g., "CPSG-C-2-500"). Hence, "limited license". In such situation, traffic that should arrive on one external interface and leave on a different external interface of the Security Gateway, will not be allowed. An Evaluation license (e.g., "CPSG-C-8-U") does not impose a limit on the number of hosts that will be protected by the Security Gateway. Therefore, more than one external interface can be configured in the Topology. Applies To: This SK replaces sk34640, sk113598 00337686 , 00352855 , 00403080 , 00352909 , 00352911 , 00373956 , 00373955 , 00352908 , 00368685 , 00352910 |