CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-27
Jahk Nah Rai Jahk Nah Rai is offline
Member
 
Join Date: 2005-11-04
Posts: 42
Rep Power: 0
Jahk Nah Rai has an average reputation (10+)
Default STATIC NAT stops working after a while

I have a Checkpoint FW1 NG FP3 box on Windows 2000 Server.

For some strange reason everything seems to work except the Static NAT entries. It would work for a while and then stop hours later. Hide NAT works well. Checking the gateway router's ARP tables reveals Incomplete for every STATIC NAT IP.

Does anyone know why Checkpoint is doing this?
Reply With Quote
  #2 (permalink)  
Old 2006-09-27
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 808
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: STATIC NAT stops working after a while

I take it you are using automatic proxy ARP? Don't. If you must use proxy ARP - and you shouldn't but sometimes can't avoid it - then manually configure the proxy ARP entries on your firewall. Don't rely on auto proxy ARP - it's too flaky.

I take it the hide nat entries are hiding behind the firewall's IP? - in which case it doesn't need to do proxy ARP.

Take a look at the various HFA release notes - I've seen a few things where they've fixed some stuff with auto proxy ARP. Sometimes it would do things like lose the entries if the interface flapped.

Check arp -a on the server, see what it's publishing. Configure all your proxy ARP entries manually, and things should work OK.

Oh and you should probably plan on moving away from FP3/Win2K, but you probably already know that....
Reply With Quote
  #3 (permalink)  
Old 2006-09-27
Jahk Nah Rai Jahk Nah Rai is offline
Member
 
Join Date: 2005-11-04
Posts: 42
Rep Power: 0
Jahk Nah Rai has an average reputation (10+)
Default Re: STATIC NAT stops working after a while

Ok so I will have to use arp -s and manually add each MAC address and IP to the Checkpoint's tables?
Understood what you mean, thanks. I will try that.
Reply With Quote
  #4 (permalink)  
Old 2006-09-27
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 808
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: STATIC NAT stops working after a while

I don't work with Windows, so I don't know exactly how to add proxy ARP with it. I think with Check Point systems you can edit the local.arp file though?

It's not really about adding entries to Check Point's tables though - it's about getting the upstream router to forward those frames to your firewall, and one way of doing that is to get your OS to send out ARP replies to requests for those NAT IPs. The other (better) way is to have routes on the upstream router.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:27.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0