CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-10
nesysen nesysen is offline
Junior Member
 
Join Date: 2006-12-17
Posts: 5
Rep Power: 0
nesysen has an average reputation (10+)
Default NGX R60, NAT and Routing question?

Hi All.
I have a Nokia IP260 with Checkpoint NGX R60 installed. There're 4 interfaces on IP260. Here's my network map:
Firewall:
IP260: eth1 --- Router --- ISP1: Lease line. (Static IP)
IP260: eth2 --- modem ADSL bridge mode ---- ISP2: ADSL (Static IP)
IP260: eth3 --- DMZ (192.168.1.0/24) -- Nat to public IP via Firewall
IP260: eth4 --- LAN (10.0.0.0/24)

I want all servers in DMZ go to internet through Leaseline link and All client in LAN go to internet through ADSL line.

How do I config on Firewall?

Rgds.
Reply With Quote
  #2 (permalink)  
Old 2007-01-10
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 808
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: NGX R60, NAT and Routing question?

Sounds like you're trying to achieve source based routing - which you can't do on a Nokia.

You can control where inbound traffic comes via your BGP advertisements, but you can have only one default route.

Looks like you need to rethink what you're trying to do.
Reply With Quote
  #3 (permalink)  
Old 2007-01-10
rayden69 rayden69 is offline
Junior Member
 
Join Date: 2006-09-18
Posts: 19
Rep Power: 0
rayden69 has an average reputation (10+)
Default Re: NGX R60, NAT and Routing question?

Through the use of NAT and 2 equal cost default routes you can achieve the goal you are trying to perform.


Hide 192.168.1.0/24 behind eth1 --- Router --- ISP1: Lease line. (Static IP)

and 10.0.0.0/24 behind eth2 --- modem ADSL bridge mode ---- ISP2: ADSL (Static IP)

if you want static nats for some of the DMZ you must make sure to use an IP available on the ISP1 network and provided to you from them.

If this is not clear enough please let me know and I can assist you in the creation of these rules/NATs.
Reply With Quote
  #4 (permalink)  
Old 2007-01-13
nesysen nesysen is offline
Junior Member
 
Join Date: 2006-12-17
Posts: 5
Rep Power: 0
nesysen has an average reputation (10+)
Default Re: NGX R60, NAT and Routing question?

Thanks alot for support.
I have a static IP addresses range of ISP1 and I config static NAT for all DMZ Server via Nokia eth1 interface and go internet through Router and Leasedline.

My ADSL Line has static IP from ISP2 and I used ADSL Modem under Bridge Mode, use Nokia connect to ISP2 via PPPoE. The Static Public IP address is on Nokia eth3.
I already config LAN (10.0.0.0/24) hide nat (automatic nat) via Nokia and behide ADSL static IP address.

Every client in LAN can connected to Internet but all connection goes through Leaseline.

I don't know why?

Any one can help me?

Thanks.
Reply With Quote
  #5 (permalink)  
Old 2007-01-13
NickBrandson NickBrandson is offline
Member
 
Join Date: 2006-12-20
Posts: 83
Rep Power: 2
NickBrandson has an average reputation (10+)
Default Re: NGX R60, NAT and Routing question?

Possibly, your default gateway is pointed to Leaseline, right?
Take a look of the Xlated Source -> logs for the LAN, it should be NATed with your ADSL-ISP2, right?


Quote:
Originally Posted by nesysen View Post
Thanks alot for support.
I have a static IP addresses range of ISP1 and I config static NAT for all DMZ Server via Nokia eth1 interface and go internet through Router and Leasedline.

My ADSL Line has static IP from ISP2 and I used ADSL Modem under Bridge Mode, use Nokia connect to ISP2 via PPPoE. The Static Public IP address is on Nokia eth3.
I already config LAN (10.0.0.0/24) hide nat (automatic nat) via Nokia and behide ADSL static IP address.

Every client in LAN can connected to Internet but all connection goes through Leaseline.

I don't know why?

Any one can help me?

Thanks.
Reply With Quote
  #6 (permalink)  
Old 2007-03-29
Steve_Martin Steve_Martin is offline
Junior Member
 
Join Date: 2007-03-25
Posts: 6
Rep Power: 0
Steve_Martin has an average reputation (10+)
Default Re: NGX R60, NAT and Routing question?

U can point the firewall to the Internet router for default gateway. If the router supports policy based routing (cisco routers do), then u can redirect traffic to different gateways based on the source IP range.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 14:15.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0