CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-10
ChrisA ChrisA is offline
Senior Member
 
Join Date: 2006-02-18
Posts: 101
Rep Power: 3
ChrisA has an average reputation (10+)
Default NATing src & dst for site-to-site AND SecureClient

This is a strange one. Not sure if it belongs in the NAT group, SecureClient group, or a little of both. Anyway, I'm looking for some pointers on how I can handle the situation below.

When users are on the company's local network, they access an externally hosted app (say, 99.99.99.99) through a site-to-site VPN. All internal resources are HIDE NATted to one public address, say 1.1.1.1. Works fine. Note: the app is only accessible through the site-to-site VPN.

When these users are working remotely and they connect SecureClient with Office Mode, they want to access the external app. I can't put the app's addr in the encrypt domain, or the site-to-site won't work. I think the only way to do this is with some fancy natting: statically nat 99.99.99.99 to x.x.x.x, put x.x.x.x in the encrypt domain. Remote user accesses x.x.x.x, session comes through SecureClient VPN, hits firewall, dest is natted to 99.99.99.99, source is natted to 1.1.1.1, session goes out over site-to-site VPN tunnel.

Will this even work? Has anyone done it successfully? Is there a better way? We do not use automatic NAT; is that required to do this sort of double natting?
Reply With Quote
  #2 (permalink)  
Old 2007-03-12
draegloth draegloth is offline
Junior Member
 
Join Date: 2006-09-30
Posts: 7
Rep Power: 0
draegloth has an average reputation (10+)
Default Re: NATing src & dst for site-to-site AND SecureClient

Hi Chris,

Do you disabled the nat inside this vpn community?

If nat is enabled on your community, although I'm not sure you can try to hide nat the office mode IP pool and mark the route all traffic through the gateway on your profile settings.

My second suggestion is that if you have a DHCP server on your local network, give the client IP addresses from DHCP server. Use the same pool with your local network.

Regards...
Reply With Quote
  #3 (permalink)  
Old 2007-03-12
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: NATing src & dst for site-to-site AND SecureClient

There is something you can try. Edit your firewall properties, go to the "Remote Access" tab.

If you can check the Hub Mode Configuration, that means that all traffic will be forced down to the firewall. This would mean that traffic to the 99.99.99.99 server would also come through the client-to-site VPN. From there it would go back into the site-to-site VPN.

You would need to NAT the SR connections with the Hide NAT too, so you might need to change your NAT rule to be:
Internal+IP pool | 99.99.99.99 | any | Hide IP | = | =

Important note: Hub mode means all SR traffic comes to the firewall, it may not be ideal for you... this means they will access the web via the firewall, etc.

If that isn't acceptable, then you can do the NAT thing you mention.
Reply With Quote
  #4 (permalink)  
Old 2007-03-12
ChrisA ChrisA is offline
Senior Member
 
Join Date: 2006-02-18
Posts: 101
Rep Power: 3
ChrisA has an average reputation (10+)
Default Re: NATing src & dst for site-to-site AND SecureClient

Thanks for your responses.

We are using Traditional VPNs, not communities. Routing all traffic through the tunnel is not an option. We are using DHCP to allocate Office Mode IP addresses in the 10.x.x.x range to our SecureClient VPN users. So in effect our NAT rule needs to be:
VPN-Pool-10.x.x.x | nat-Dest-IP | nat-Src-IP (hide) | real-Dest-IP (static)

Is this method of double NATting possible? Should it work?
Reply With Quote
  #5 (permalink)  
Old 2007-03-13
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: NATing src & dst for site-to-site AND SecureClient

Yes it is possible, yes it should work.

The only thing that you need to make sure is that the firewall routes the packet correctly, but I don't see that being an issue with translate on client side.

If it doesn't work, try adding routing from nat-Dest-IP to real-Dest-IP.
Reply With Quote
  #6 (permalink)  
Old 2007-03-13
ChrisA ChrisA is offline
Senior Member
 
Join Date: 2006-02-18
Posts: 101
Rep Power: 3
ChrisA has an average reputation (10+)
Default Re: NATing src & dst for site-to-site AND SecureClient

It worked great. Thank you!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:35.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0