CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-05
clarkeyi clarkeyi is offline
Member
 
Join Date: 2005-12-18
Posts: 44
Rep Power: 0
clarkeyi has an average reputation (10+)
Default NAT General Question

Hello
I have a question on NAT - I have a web server in my DMZ (172.16.0.25) and use a Nokia firewall. If I want incoming NAT to this server do I need to get the mac address of my external firewall interface and create an arp entry in voyager referencing the mac address and nat'd ip address.
Then do I have to also add athe command set staticroute 89.x.x.x/32 nexthop gateway address q72.16.0.25 priority 1 on....and then also create nat'd hosts in my checkpoint firewall hosts within the smartcenter server. Does this sound correct steps as it seems longwinded to create manual static entry.

Thanks
Reply With Quote
  #2 (permalink)  
Old 2007-02-05
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 891
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: NAT General Question

Try going to the NAT tab on the web server object, setting Static and entering in the public IP address and selecting the Install On to the firewall. Then install the policy.

That will create an automatic proxy ARP entry on a Nokia as well. The route should be there already since it presumably is on a directly connected interface.

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-02-06
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: NAT General Question

Clark, what you described is the "old" way of doing NAT, from before the "Translate on client side" and "Automatic ARP configuration" options.

Unless you are using a really old version, up to v4.1 if memory serves, you will only need to do what Ray described.

If you have issues, go on "Policy->Global Properties" on the NAT tab and check if the options mentioned above are ticked.
Reply With Quote
  #4 (permalink)  
Old 2007-02-13
antonyso88 antonyso88 is offline
Senior Member
 
Join Date: 2006-11-23
Posts: 158
Rep Power: 2
antonyso88 has an average reputation (10+)
Default Re: NAT General Question

I have a similar question. If i use manual destination NAT, is it still need to add route and arp mac address? I am using R61.
Reply With Quote
  #5 (permalink)  
Old 2007-02-13
kva.kva kva.kva is offline
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: NAT General Question

If you use manual NAT you need add arp entries.
Good doc - Firewall and SmartDefense User Guide R61 -> Network Address Translation (NAT) -> Check Point Solution for Network Address Translation
Reply With Quote
  #6 (permalink)  
Old 2007-02-13
antonyso88 antonyso88 is offline
Senior Member
 
Join Date: 2006-11-23
Posts: 158
Rep Power: 2
antonyso88 has an average reputation (10+)
Default Re: NAT General Question

Thx a lot!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 14:36.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0