CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-30
Junior Member
 
Join Date: 2006-05-30
Posts: 5
Rep Power: 0
rendl42 has an average reputation (10+)
Default PAT problem

Hey there,

I have an ADSL modem with a static ip:
adsl-ext: 155.55.55.55
adsl-dmz: 10.1.1.1

My Checkpoint NGX firewall:
CPNG-ext: 10.1.1.2
CPNG-int: 192.168.0.1

And I have a webserver on the internal network (please disregard the obvious security problem of having it there).
webserver: 192.168.0.250

I created a forwarding rule on the ADSL modem to pass all port 80 requests through to the firewall.

I have a NAT Rule on the firewall as follows:

any -> CPNG-ext:http -> source:original destination:webserver service:original

Then I connect from external with a browser and get a 404. I see a log entry for the FW rule permitting the communication, but the sniffer on webserver shows no packets. Appears the forwarding is broked.

Any suggestions?

Thanks!
Reply With Quote
  #2 (permalink)  
Old 2006-05-30
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: PAT problem

Do you using doble NAT?
Error 404 is better than nothing. That mean that the server is accessible, but contians no files.
Reply With Quote
  #3 (permalink)  
Old 2006-05-30
Junior Member
 
Join Date: 2006-05-30
Posts: 5
Rep Power: 0
rendl42 has an average reputation (10+)
Default Re: PAT problem

Actually come to think of it, I just "unable to connect to remote host".

I am not familiar with double NAT. I simply NAT on the way in (static as outlined above) and all internal systems are on a hide NAT rule (auto NAT).
Reply With Quote
  #4 (permalink)  
Old 2006-05-30
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: PAT problem

The problem is that you doing NAT 2 times on the DSL Modem/router and on the Firewall. Try to stuck with NAT only on one box. Reconfigure you DSL Modem/Router to a bridge mode. This will bring "real" (public) interfaces on the Firewall.
Use you port nat rule than.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:02.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0