CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-10-29
vt2006 vt2006 is offline
Junior Member
 
Join Date: 2006-10-29
Posts: 5
Rep Power: 0
vt2006 has an average reputation (10+)
Default Cannot reach webserver from internal network

Hi,

Originally I did static for a webserver, i.e, 1.1.1.80 > 192.168.1.80. Things were working fine before. Users from Internet or internal network could reach the webserver through the real IP "1.1.1.80".

Recently I changed to use port address translations: -

Original Translated
SRC DST SERVICE SRC DST SRV
Any 1.1.1.80 80 Original 192.168.1.80 Original
Any 1.1.1.80 5900 Original 192.168.1.59 Original

After that, Users from Internet can reach the webserver but users in the internal segment 192.168.1.x cannot reach the webserver via the real IP "1.1.1.80". Could any expert give hands on this and is it possible to explain why? Thanks a lot.

Regards,
Reply With Quote
  #2 (permalink)  
Old 2006-10-29
Acidio Acidio is offline
Senior Member
 
Join Date: 2006-10-23
Location: Auckland, NZ
Posts: 110
Rep Power: 2
Acidio has an average reputation (10+)
Default Re: Cannot reach webserver from internal network

I'm assuming the previous NAT method was automatic. If that was the case, the firewall automatically creates ARP entries for the public address.

If you have disabled the automatic NAT from the object, then these advertisements will no longer be in effect.

To re-enable the HTTP access try adding the automatic static NAT back to the web server object. Don't delete you PAT entries though. (I'm assuming these are above all your other rules.) Since the NAT rules are read from top to bottom, your PAT rules should work fine.

You should see the access to the web server via the public address now work OK.
Reply With Quote
  #3 (permalink)  
Old 2006-10-30
vt2006 vt2006 is offline
Junior Member
 
Join Date: 2006-10-29
Posts: 5
Rep Power: 0
vt2006 has an average reputation (10+)
Default Re: Cannot reach webserver from internal network

Hi,

1st of all, thanks for your reply. However, it still doesn't work after I enabled the automatic NAT for the webserver. May be I should provide more details: -

network
--------
firewall lan: 192.168.1.1/24
firewall wan: 1.1.1.254
router: 1.1.1.1

nat
---
src dst srv tsrc tdst tsrv
any 1.1.1.80 80 orig 192.168.1.80 orig
any 1.1.1.80 5900 orig 192.168.1.59 orig
192.168.1.80 any any (s)192.168.1.80 orig orig <- automatic rule
any 192.168.1.80 any orig (S)192.168.1.80 orig <- automatic rule
192.168.1.0 192.168.1.0 any orig orig orig <- automatic rule
192.168.1.0 any any orig (H)192.168.1.0 orig <- automatic rule

rules
----

src dst srv action
any 1.1.1.80 80, 5900 permit
192.168.1.0 any any permit

Please kindly advise.

Regards,
Reply With Quote
  #4 (permalink)  
Old 2006-10-30
Acidio Acidio is offline
Senior Member
 
Join Date: 2006-10-23
Location: Auckland, NZ
Posts: 110
Rep Power: 2
Acidio has an average reputation (10+)
Default Re: Cannot reach webserver from internal network

OK, I see what I forgot to mention. Try adding rule that looks like this:
src dst service action track
any 192.168.1.80 HTTP accept log

You'll need to do this since NAT occurs first. This should help.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:22.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0