Re: uni-directional nature of hide nat If the policy permits access to your internal network from the external network, and you actually have a route from the external network to the internal network then yes you can access the internal network from the internal network. As you are going to the actual IP of the internal box then you are not Natting when you do this. Check Point has no concept of internal, external, or security level on the interfaces like Cisco does, which is why can do this on a Check Point, if the policy permits. Remember however that normally from the Internet there will be no route to your private internal network, so isn't a real issue as normally you would not have a policy from external to internal network. |