CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    R70 CCSA Courses Starting (2010) 6/7, 7/12, 8/9, 10/11, 11/8, 12/6.  R70 CCSE Courses Starting (2010) 8/16.
2. CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn and Facebook.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 2010-02-24
Junior Member
 
Join Date: 2006-04-27
Posts: 6
Rep Power: 0
BenRad has an average reputation (10+)
Default NAT prevents VPN traffic from using tunnel.

I've always had the NAT on our FW set up the following way: Our internal LAN object is set to use Automatic Address Translation rules to hide behind an external IP address and it's set to Install on Gateway: *All. I'm not sure this is the right way to set it up, but that's how it is.

So now, when I attempt to route internal traffic over our VPN (Cisco 3005) which is located on our DMZ, the VPN refuses to send the traffic over the tunnels because our internal addresses are being NATed to external addresses and don't match up with the other end of the tunnel.

I'm trying to create a rule that prevents the internal addys from being NATed. Is this possible or because of the way I have things set up (see above) do I need to change things around?
Reply With Quote
  #2 (permalink)  
Old 2010-02-24
Senior Member
 
Join Date: 2006-01-25
Posts: 1,358
Rep Power: 6
melipla has an average reputation (10+)
Default Re: NAT prevents VPN traffic from using tunnel.

Yes, the automatic NAT rules will hit first. You can disable NAT for a VPN community: SmartDashboard -> IPSec VPN -> Community Properties -> Advanced Settings -> Advanced VPN Properties -> Disable NAT inside the VPN Community

That should take precedence over the Auto-NAT rules.
__________________
Its all in the documentation.
Reply With Quote
  #3 (permalink)  
Old 2010-02-24
Senior Member
 
Join Date: 2007-06-04
Posts: 1,560
Rep Power: 5
mcnallym has an average reputation (10+)
Default Re: NAT prevents VPN traffic from using tunnel.

I believe from your description that the VPN is terminated upon the Cisco3005Concentrator, which is located on the DMZ then the community trick doesn't work as that is for when the VPN is terminated upon the Check Point. If the VPN is from the Check Point to the Cisco 3005 then that will work fine.

If however the VPN terminates upon the Cisco 3005 and is off to another device for the VPN then what you do is as follows.

All you need to do is create a NAT rule at the top of the NAT section.

Src=Internal_Network
Dst=Far_End_VPN_Tunnel_Network
Srv=Any

xlateSrc=Original
xlateDst=Original
xlateSrv=Original

This will ensure that any traffic going from the Internal Network, with a destination of the far end of the VPN tunnel is not Address Translated as you tell it to keep the Src as Original.

As the traffic hits that NAT rule as it is at the top then the Automatic NAT rule is not encountered.

Traffic to the Internet or other destinations does not hit the No NAT rule and so the traffic is still NATted.
Reply With Quote
  #4 (permalink)  
Old 2010-02-25
Junior Member
 
Join Date: 2006-04-27
Posts: 6
Rep Power: 0
BenRad has an average reputation (10+)
Default Re: NAT prevents VPN traffic from using tunnel.

@mcnallym Fantastic.

That's exactly what I was looking for. Much appreciated.
Reply With Quote
Reply

Tags
dmz, nat external, vpn

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:24.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.1