CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-06
bod43 bod43 is offline
Junior Member
 
Join Date: 2008-04-23
Posts: 4
Rep Power: 0
bod43 has an average reputation (10+)
Default Nokia cluster hide NATs to physical address

Hello,


Hope this is the correct forum for this rather than the Nokia one.

I have just installed a Nokia cluster and all seems pretty reasonable except that the NATted address for outbound Internet traffic is the physical address of the particular node and NOT the cluster address which would seem to be required. I have left the properties of the network being NATted as
Hide Behind gateway

and not specified an address.

Clearly I could fix it by entering the cluster address however I do not wish to do this as I have a DMZ that I want to NAT to as well and it would then require manual NAT rules.

Is there anthing I am missing?.
Reply With Quote
  #2 (permalink)  
Old 2008-05-06
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 923
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Nokia cluster hide NATs to physical address

No you are seeing what I would expect.

If you use an AutoNAT and then specify Hide NAT and a specific IP address, why would that need Manual NAT then for the DMZ?

Why could you still not use AutoNAT and Static for the DMZ.
Reply With Quote
  #3 (permalink)  
Old 2008-05-08
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 272
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: Nokia cluster hide NATs to physical address

hi i am new to checkpoint and i want to know when we are having a cluster and we are using hide nat behind the gateway. then the packets will be natted to the external interface ip address. so when the return traffic comes back to the gateway will the gateway process the packet.

cause i guess as per the documentation when we configure cluster the outside router points route to the internal networks or natted address pointing to the virtual ip on the external interface.

so is it necessary for us to use the virtual ip address as the nat address.

i am not sure abt this can someone pls guide me on this.,

regards

sebastan
Reply With Quote
  #4 (permalink)  
Old 2008-05-08
bod43 bod43 is offline
Junior Member
 
Join Date: 2008-04-23
Posts: 4
Rep Power: 0
bod43 has an average reputation (10+)
Default Re: Nokia cluster hide NATs to physical address

Thanks for the reply.

mcnallym said
"why would that need Manual NAT then for the DMZ"
I did not explain properly. The 'DMZ' has public addresses and I want to hide NAT from the Internal networks to the DMZ and to the Internet.

So it looks like I should:

On 'Internal' Network Objects choose
Add Automatic rules and specify the Cluster IP address to cover the Internet.
Add manual rules for the Natting to my 'DMZ'. This is easy enough.
Its not really a DMZ but I thought that was the easiest way to describe it.

Thanks again.
Reply With Quote
  #5 (permalink)  
Old 2008-05-08
bod43 bod43 is offline
Junior Member
 
Join Date: 2008-04-23
Posts: 4
Rep Power: 0
bod43 has an average reputation (10+)
Default Re: Nokia cluster hide NATs to physical address

Quote:
Originally Posted by sebastan_bach View Post
hi i am new to checkpoint and i want to know when we are having a cluster and we are using hide nat behind the gateway. then the packets will be natted to the external interface ip address. so when the return traffic comes back to the gateway will the gateway process the packet.

cause i guess as per the documentation when we configure cluster the outside router points route to the internal networks or natted address pointing to the virtual ip on the external interface.

so is it necessary for us to use the virtual ip address as the nat address.

i am not sure abt this can someone pls guide me on this.,

sebastan

"then the packets will be natted to the external interface ip address. so when the return traffic comes back to the gateway will the gateway process the packet"

I would think that in most circumstances you would want
the outgoing packets hide natted to the Cluster address.
Otherwise in the event of a failover or dynamic load re-balance
the sessions will disappear.

"so is it necessary for us to use the virtual ip address as the nat address."
So yes - I think so.
Reply With Quote
  #6 (permalink)  
Old 2008-05-14
bod43 bod43 is offline
Junior Member
 
Join Date: 2008-04-23
Posts: 4
Rep Power: 0
bod43 has an average reputation (10+)
Default Re: Nokia cluster hide NATs to physical address

IPSO Cluster R65

I am still struggling with this.

If I have:-
- Hide nat for network set to "Hide behind gateway"

- Cluster Object 3rd party configuration
Hide Cluster member's outgoing traffic behind the Cluster's IP address.

I still get the source address of the traffic as one of the physical addresses depending on the gateway in use.

If I force the use of the Cluster address with
Hide nat for network set to "Hide behind IP address" and specify the
Cluster address then I get the NAT I want.

However - I also get web browsing performance issues that I think is related to log messages with:-

Information: TCP packet out of state: Unexpected post SYN packet - RST or SYN expected tcp_flags: ACK

I get a normal "Accept" from one node and the above fail from the other node at the exact same time.

I have found:-
Solution ID: sk34203 Previous Next
Out of State drops on Nokia IPSO Clustering (not VRRP)

The IPSO OS has a parameter that can be set to ensure that the Security Gateway performs the Flush and Ack, so that the SYN can be "sync'd" prior to the asymmetric SYN-ACK returning to the Security Gateway.

To enable "on the fly":
ipsctl -w net:ip:cluster:force_flush 1

I have also disabled Dynamic work assignment in favour of static.

This has made no difference to the "Unexpected post SYN packet "
messages or the performance.

Performance is fine and there are no messages if the NAT is left as
- Hide nat for network set to "Hide behind gateway"

But as described I cannot see that failover can occur with the
observed NAT behaviour.

VRRP here we go I think.

Thanks.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:03.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0