CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-06-06
simon84 simon84 is offline
Junior Member
 
Join Date: 2006-06-06
Posts: 1
Rep Power: 0
simon84 has an average reputation (10+)
Default FW-1 Portforwarding woes

Hi everyone,

Im running 4.1SP6 on an IP330. I configured the external if with 10.10.1.14/24 and one internal if with 192.168.0.1/24. I have a test machine with IP 192.168.0.2 connected there. Connection to and through the firewall is fine and I've been able to setup NAT for the internal 192.168.0.0/24 network with the following Address translation rule : src localnetwork(192.168.0.0/24), dst any, service any/src fw3(hide), dst original, service original.
But I can't get a simple portforwarding to work. I would like to forward a single port, for example 666/tcp to a machine on the internal network on the same port. I've tried this rule : src any , dst fw3, service bbb(666/tcp)/src original, dst Neptun(static/192.168.0.2), service original.
I tried connecting to 666/tcp on 10.10.1.14 from a machine within the 10.10.1.0/24 network, but I just get connection refused and ethereal capturing on the 192.168.0.2 machine doesnt show anything either.
Firewall-1 logfile shows an entry with the corresponding xlatesrc,xlatedst,xlatesport and xlatedport entries.
What else can I check/am I doing wrong?

Greetings,

Simon
Reply With Quote
  #2 (permalink)  
Old 2006-06-06
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 3
Sergej has an average reputation (10+)
Default Re: FW-1 Portforwarding woes

You need to add both - NAT (PortForwarding) and Security Rule.
Reply With Quote
  #3 (permalink)  
Old 2006-06-06
wandererz wandererz is offline
Junior Member
 
Join Date: 2006-06-06
Posts: 9
Rep Power: 0
wandererz has an average reputation (10+)
Default Re: FW-1 Portforwarding woes

Is your rule setup before or after your stealth rule? (needs to be before)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:50.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0