CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-05
Junior Member
 
Join Date: 2006-09-30
Posts: 7
Rep Power: 0
draegloth has an average reputation (10+)
Default disabled static nat still seems to be working

Hi guys,

I have a star vpn topology and the end points are vpn edge boxes with running firmware version of 6.5.43.

I have disabled NAT inside the VPN community.

I've a sip proxy on the center site. I've been natted the machine on an internet IP for some testing, after testing I've disabled that nat rule.

The problem is, when I capture sip packets i saw that the IP address on the sip packets form egde to center contains the lokal IP address of the sip proxy. However on the return packets I saw the natted IP address when I making tests. I've checked the objects_5.0.c file but I saw nothing related to this IP addr.

Do you have any idea how to clear this natted IP address?

Regards...
Reply With Quote
  #2 (permalink)  
Old 2007-03-05
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: disabled static nat still seems to be working

Quote:
Originally Posted by draegloth View Post
Do you have any idea how to clear this natted IP address?
The R60 HFA 05 release notes give a pretty clear picture of what is (and wasn't) supported for NAT regarding SIP. However I'm not sure how this translates into Edge versions.
__________________
Its all in the documentation.
Reply With Quote
  #3 (permalink)  
Old 2007-03-05
Junior Member
 
Join Date: 2006-09-30
Posts: 7
Rep Power: 0
draegloth has an average reputation (10+)
Default Re: disabled static nat still seems to be working

Sorry guys it seems that i forget to give the version on my center site. The center site version is R61 HFA01.
Reply With Quote
  #4 (permalink)  
Old 2007-03-05
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: disabled static nat still seems to be working

You probably haven't compiled the policy for the Edge's, so they are still fetching a policy with the NAT rule active.
Reply With Quote
  #5 (permalink)  
Old 2007-03-05
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: disabled static nat still seems to be working

Seems to me that NAT is not cleared when the rule is removed and a policy is pushed. I think you have to wait a bit for it to expire.

If you waited more than an hour, this probably is not it.

Ray
Reply With Quote
  #6 (permalink)  
Old 2007-03-07
Junior Member
 
Join Date: 2006-09-30
Posts: 7
Rep Power: 0
draegloth has an average reputation (10+)
Default Re: disabled static nat still seems to be working

I waited more than 3 days however the result still the same. I think that this is a bug for sip.
Reply With Quote
  #7 (permalink)  
Old 2007-03-07
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 909
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: disabled static nat still seems to be working

Yeeesss, I think three days is more than enough. :-)

Ray
Reply With Quote
  #8 (permalink)  
Old 2007-03-08
Senior Member
 
Join Date: 2006-01-25
Posts: 926
Rep Power: 3
melipla has an average reputation (10+)
Default Re: disabled static nat still seems to be working

Quote:
Originally Posted by draegloth View Post
I waited more than 3 days however the result still the same. I think that this is a bug for sip.
Most likely...

By chance, if you log into the edge device and go to Setup -> Tools -> Diagnostics, do you see the NAT rule at the bottom of the page?

Also, which edge firmware are you using?
__________________
Its all in the documentation.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:21.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0