CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-20
thebuffman thebuffman is offline
Junior Member
 
Join Date: 2006-06-28
Posts: 28
Rep Power: 0
thebuffman has an average reputation (10+)
Default NAT Ceased Working

Wondering if somewhere here with good NAT experience can assist me. The setup I am using is configured to do Static Natting without having to manage proxy arp tables. This is how.
  • I have a VPN established between a client.
  • The client accesses multiple servers behind our firewall.
  • The servers each have a publicly assigned address.
  • The firewall automatically translates the server addresses because it bypasses any arp request by using the vpn tunnel direct connection

Please trust me on this that proxy arp is really not necessary. There was a posting by Northlandboy that really delved into the reason why proxy arp is not necessary but I won't get heavy into that.

Anyhoo all was working until 10 days ago and now the client can no longer connect to our servers. I saw NOTHING in the logs which really alarmed me. I performed a tcpdump to gather information between the two tunnel gateways and did verify that the client's gateway is forwarding packets through to the tunnel to our site but our firewall doesn't seem to know what to do with the packets (there are no drop packets in the logs either...the logs sho nothing). I cannot figure out what happened. Just stopped working for no apparent reason. I am on NG AI R55.

I can probably get this working by instituting proxy arp but to do this I will have to create a new virtual network on my firewall's interface and assign it an ip address inside of the subnet I am NATing. I don't want to go through all of this manual trouble.

Any insight?

Last edited by thebuffman; 2007-02-20 at 13:43.
Reply With Quote
  #2 (permalink)  
Old 2007-02-21
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: NAT Ceased Working

Any chance someone ticked the "Disable NAT inside the VPN community"? Not sure this exists for R55, but...

Also if you want to use proxy arp, you don't need virtual interfaces, you can just add a route to that network and point it to an IP of the subnet being translated, to make sure the packets are routed to the right interface.

So if your servers are in the 192.168.1.0/24 and you are "NATing" with 1.1.1.0/24 , you could just do:

route add 1.1.1.0 nm 255.255.255.0 192.168.1.1

Maybe your client changed something on their side?
Reply With Quote
  #3 (permalink)  
Old 2007-02-21
thebuffman thebuffman is offline
Junior Member
 
Join Date: 2006-06-28
Posts: 28
Rep Power: 0
thebuffman has an average reputation (10+)
Default Re: NAT Ceased Working

Thanks for the timne and insight MarioL. It seems now that our client actually didn't have an issue communicating. They let us know today. There was probably something on their end.

I am alarmed as to why I see nothing in my logs though. This is bad. Why would I stop logging this traffic all of a sudden. *sigh* My job never gets easier.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:49.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0