I have a MFE 410F V8.1 with two Internet links.
My scenario is:
Interface em0 is 18.104.22.168/29 and the Lan Router Interface is 22.214.171.124
Interface bge0 is 126.96.36.199/29 and the Lan Router Interface is 188.8.131.52
The default gateway of my MFE is 184.108.40.206.
So, please let me to comment you my issues:
1. Both Internet links are provided by the same provider and I don´t know what IP address could I monitor in order to configure the ISP redundancy correctly.
What happens if I don´t configure monitor addresses and I only configure the default and backup routes?
2. This is the most important item for me right now.
I have some policies permitting access from Internet to my partners and I´m using Public IP addresses of both Internet Links for it. For instance, for https access from Internet I´m using 220.127.116.11 and for Terminal Server access I´m using 18.104.22.168.
With other firewall that configuration worked well but with my MFE this is not working. I found the the following log:
2011-03-21 19:29:35 -0500 f_kernel_ipfilter a_general_area t_nettraffic p_major
hostname: fw.local event: session end application: <Unknown TCP>
netsessid: a34244d87ed6f src_geo: CO srcip: 22.214.171.124 srcport: 28220
srczone: Internet2 protocol: 6 dstip: 192.168.3.3 dstport: 3389
dstzone: Servidores bytes_written_to_client: 0 bytes_written_to_server: 0
rule_name: <Pending Application Identification> cache_hit: 0
start_time: 2011-03-21 19:29:35 -0500
2011-03-21 19:29:38 -0500 f_kernel a_nil_area t_netprobe p_major
hostname: fw.local event: TCP SYN/ACK netprobe src_geo: CO
srcip: 126.96.36.199 srcport: 3389 srczone: Internet2 dst_geo: CO
dstip: 188.8.131.52 dstport: 28220 protocol: 6 interface: lo7
reason: Received a SYN/ACK packet that did not match a pending outgoing connection. This may indicate a scanning attack or routing problem.
Does MFE not support sticky connections? Any idea in order to solve this issue?
Thanks in advance.