CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-07-03
wiz4rd wiz4rd is offline
Member
 
Join Date: 2006-06-19
Posts: 32
Rep Power: 0
wiz4rd has an average reputation (10+)
Default Static Nat Manual

Hello Guys,

I'm in trouble with static nat manual on Checkpoint NGX R60.

I should nat a client (10.x.x.x) with public address (212.x.x.x)

I have created two rules of manual nat 10.x.x.x (source) destination 213.x.x.x | 212.x.x.x (source nat) 213.x.x.x (original ip)

and just below i have added 213.x.x.x (source) 212.x.x.x (destination ) | 213.x.x.x (original) 10.x.x.x (nat destination)

When i see log tracker i can see that nat works, but seem that return of packets has problems.

Under global proprieties i have checked "merge manual nat" but i have the same problem. Maybe that depends from local.arp ? Is it still necessary from Checkpoint 4.1 ? If yes how can do to configure local.arp ?

Thank you in advanced
Reply With Quote
  #2 (permalink)  
Old 2006-07-03
gfont96 gfont96 is offline
Member
 
Join Date: 2005-08-24
Posts: 72
Rep Power: 4
gfont96 has an average reputation (10+)
Default Re: Static Nat Manual

Hello,

I have same issue in win2k. On splat I think you need to add manual arp entry on module.

I think it goes something like

'arp -s <NAT PUBLIC IP> <MAC Address of external interface>.'

Good luck

George
Reply With Quote
  #3 (permalink)  
Old 2006-07-03
wiz4rd wiz4rd is offline
Member
 
Join Date: 2006-06-19
Posts: 32
Rep Power: 0
wiz4rd has an average reputation (10+)
Default Re: Static Nat Manual

Thanks,

I have already done but doesn't works.

I have even enable to 1 the /proc/sys/net/ipv4/conf/proxy_arp but the problem is the same..

Thank you

GL
Reply With Quote
  #4 (permalink)  
Old 2006-07-04
wiz4rd wiz4rd is offline
Member
 
Join Date: 2006-06-19
Posts: 32
Rep Power: 0
wiz4rd has an average reputation (10+)
Default Re: Static Nat Manual

Resolved :D!,

You must enable the multicast mac-address (the same of clusterxl) for the ip address natted on router .
after that arp -s <ip natted><multicast-ip-of-clusterxl> on checkpoint ngx

All works now fiuu :P

Thank you
Reply With Quote
  #5 (permalink)  
Old 2006-07-08
vijayant vijayant is offline
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 131
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: Static Nat Manual

Hi WIZ

I have used the NATed public address as the secondary IP on the external interface, it works. In my case the nated public IP and the external interface IP both belong to the same subnet.

Can you please explain more abt what u did.. How to know the multicast mac address of an interface ? I am using normal workstation with windows 2000 server for Firewall as well as Smartcenter server.

vijayant
Reply With Quote
  #6 (permalink)  
Old 2006-07-08
wiz4rd wiz4rd is offline
Member
 
Join Date: 2006-06-19
Posts: 32
Rep Power: 0
wiz4rd has an average reputation (10+)
Default Re: Static Nat Manual

Quote:
Originally Posted by vijayant
I have used the NATed public address as the secondary IP on the external interface, it works. In my case the nated public IP and the external interface IP both belong to the same subnet.

vijayant

I have used multicast address beacuse I had a cluster of checkpoint (01-00-5e..multicast address).
I think that you have added an alias on your interface for the nat but it isn't the right way for the nat.
You should explain better your situation..cluster,version of checkpoint etc etc..
Reply With Quote
  #7 (permalink)  
Old 2006-07-12
hahasasa hahasasa is offline
Junior Member
 
Join Date: 2005-08-16
Posts: 5
Rep Power: 0
hahasasa has an average reputation (10+)
Default Re: Static Nat Manual

command: arp -s [IP] [MAC] pub

should work


In Nokia,it works well.

But this command never works in SecuPlatform(R55)&my linux(AS4.2)

I tried to dump the arp req&reply,and found it never answer...

Puzzling........


So, i have to use a secoundary ip for arp pub
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:26.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0