CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Content Security/Security Servers/CVP/UFP
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-03-16
dgrattan dgrattan is offline
Junior Member
 
Join Date: 2006-02-14
Posts: 1
Rep Power: 0
dgrattan has an average reputation (10+)
Default Changing Source Address when using FTP Security Server

I have Checkpoint NG AI R55p running on a Nokia IP 380 (IPSO 4.0). I have three active interfaces.

eth1c0: connects to ISP router, uses 192.168.100.10 address
eth2c0: connects to internal router, uses 172.18.100.xx address
eth3c0: connects to "DMZ", uses registered 24 bit address range

I just added rules to allow internal users to authenticate at the firewall and FTP out to any public FTP server.

radius_users@int_network -> NOT int_network -> FTP -> User Auth

The authentication piece works great but connection to external server fails. Tracker logs show outbound FTP being permitted from an internal 172.18.100.xx source address destined to a public FTP server. Trace between firewall and ISP router (off eth1c0) shows the source address is the IP of eth1c0 and the destination IP address is the public FTP server. Connection fails because public FTP server can't respond to RFC1918 source address.

I added a manual NAT rule to translate the source address of all FTP traffic from any internal source address destined to any address to the eth3c0 address.

int_network -> *Any -> FTP : eth3c0_ip -> =Original -> =Original

Had no effect. My source address is still the address IP of eth1c0. I tried changing the NAT rule to translate the source address of all FTP traffic sourcing from the address of eth1c0 destined to any address to the eth3c0 address.

eth1c0_ip -> *Any -> FTP : eth3c0_ip -> =Original -> =Original

Also had no impact.

Can I force outbound traffic from the FTP Security server to use a different source address or interface?
Reply With Quote
  #2 (permalink)  
Old 2006-03-17
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 3
Lackie has an average reputation (10+)
Default Re: Changing Source Address when using FTP Security Server

Quote:
Originally Posted by dgrattan
eth1c0: connects to ISP router, uses 192.168.100.10 address
eth2c0: connects to internal router, uses 172.18.100.xx address
eth3c0: connects to "DMZ", uses registered 24 bit address range
Call me confused but from your description it appears that you have the 192.168.100.10 address on your External network? Is that correct?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:17.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0