CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-12-29
Junior Member
 
Join Date: 2005-10-31
Posts: 4
Rep Power: 0
peteralm has an average reputation (10+)
Default NAT with MS AD trust in corporate network

We do have a problem with one direction of 2-way trust between NT 4 local domain and Active Directory corporate domain. A 2-way trust has been set up succesfull. I think the problem might has something to do with our firewall and the fact that we NAT our internal secure NT4 pdc address.

Situation:
Our firewall CP NG AI R55 serves 3 zones. Unsecure (the corporate Active Directory network), DMZ (our public zone where an AD DC with PDC emulator function for our location is residing and the secure zone (where the PDC from our NT4 domain is residing). The secure zone addresses are not routable to the corporate network (unsecure), but are on our dmz.

When browsing from NT4 PDC to AD it works fine.
When browsing from AD domain to our NT4 domain access is denied (RPC server is unavailable). I have the feeling that NAT is part of the problem.

First tried using static nat on NT4 pdc:
NT4 pdc secure -> any (dmz or unsecure) xlates NT4 pdc dmz address -> any
which created the 2 automatic rules for translating network traffic.

Changed this to static nat rules manual.
unsecure -> NT4 pdc dmz xlates unsecure -> NT4 pdc secure
NT4 pdc secure -> unsecure xlates NT4 dmz adres -> unsecure

I suspect the AD DC in the dmz might not know the NT4 pdc server by it's NAT address because that address is not a real server, but netdom query and ping from this AD DC towards our NT4 domain does give the proper result (I think the firewall proxies as being the server in dmz on requests from dmz machines?). Connecting (user manager) however gives access denied.

Any help would be appreciated.
Reply With Quote
  #2 (permalink)  
Old 2007-01-14
Member
 
Join Date: 2006-12-20
Posts: 83
Rep Power: 2
NickBrandson has an average reputation (10+)
Default Re: NAT with MS AD trust in corporate network

What services/ports are allowed for such connection?
There are some "Special Services" for AD & Exchange. Please check out the MS-RPC Service. Use these services instead of allowing the ports.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:18.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0