CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-14
futures futures is offline
Junior Member
 
Join Date: 2006-10-03
Posts: 9
Rep Power: 0
futures has an average reputation (10+)
Default Traffic Between Ports

IP390 (4 ports) running NGX R61.

I am by no means a CP expert, and so may be missing something very simple here.

However, when this box was set up, we had the ports as follows:

Port 1 - LAN
Port 2 - DMZ
Port 3 - Internet
Port 4 - Spare

We have since had the need to configure the 4th port for a second LAN, so we now have:

Port 1 - LAN 1
Port 2 - DMZ
Port 3 - Internet
Port 4 - LAN 2

We need certain traffic to go between LAN 1 and LAN 2 and for both LANs to access the internet.

I have set up rules in SmartDashboard, and traffic is indeed functioning fine between LAN 1 and LAN 2. However, for some reason, I cannot for the life of me get Port 4 (LAN 2) to access the internet (on Port 3).

I have set up the rules, checked, double checked and trashed and started again, but can still not get this to function.

I assume (maybe wrongly) that because LAN 1 and LAN 2 can communicate, that the port is configured correctly, in which case I am puzzled as to why LAN 2 cannot access the internet.

I have watched in SmartView Tracker and there are no blocks happening. In fact you see the DNS request (when you try and hit a website) being allowed (so it can go off to the internet and resolve the address), but nothing else. DNS times out eventually, and nothing else ever shows in the Tracker.

Can anyone offer any suggestions on what might be the cause, or what direction to look in.

Thank you in advance.
Reply With Quote
  #2 (permalink)  
Old 2007-02-14
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 347
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Traffic Between Ports

Have you created NAT hide for LAN 2 when going out to the Internet?

Usually what I do is:
1 - Create a group with all my networks (for example "Allnets")
2 - Create automatic NAT for public servers
3 - Create manual NAT for the hides

NAT rules:
Allnets | Allnets | any | = | = | =
[Automatic static rules here]
Allnets | any | any | Hide on external FW ip | = | =
Reply With Quote
  #3 (permalink)  
Old 2007-02-14
futures futures is offline
Junior Member
 
Join Date: 2006-10-03
Posts: 9
Rep Power: 0
futures has an average reputation (10+)
Default Re: Traffic Between Ports

Thank you.

It was the NAT that I had missed out!

Can't believe I spent so long on something so simple :-)
Reply With Quote
  #4 (permalink)  
Old 2007-02-14
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 347
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Traffic Between Ports

Glad I could help.

I always create my own log filter (or query or whatever it's called now) and get the "Xlated stuff" and NAT rule to show, this helps a lot since it then shows the NAT stuff by default and prevents me forgetting about those bits.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:03.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0