CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-03-29
Junior Member
 
Join Date: 2006-06-05
Posts: 6
Rep Power: 0
fabwhack has an average reputation (10+)
Default Static NAT to SMTP server

I'm going crazy trying to get this working; I've searched around and followed instructions given to others but I just can't get this working:

NGX R61 on a Nokia IP265. Trying to get SMTP from a public IP address to an internal SMTP server. I've created two rules:

Security rule:

Source: Any
Destination: public IP of SMTP server (also tried putting the internal address in here)
Service: SMTP
Action: accept

Address translation:

Original Source: Any
Original Destination: public IP of SMTP server
Original Service: SMTP
Translated Source: = Original
Translated Destination: private IP of SMTP server
Translated Service: = Original

it just DOESN'T work. Automatic hide and static NAT works fine, but in the case I'd like to translate just SMTP stuff from this address - we may have other services on the address in the future going to different boxes.

What am I doing wrong?
Reply With Quote
  #2 (permalink)  
Old 2007-03-29
Senior Member
 
Join Date: 2006-06-28
Posts: 140
Rep Power: 3
david has an average reputation (10+)
Default Re: Static NAT to SMTP server

when you setup the static NAT rule do you have one for outbound?

i.e.

Original Source: private IP of SMTP server
Original Destination: any
Original Service: SMTP
Translated Source: = public IP of SMTP server
Translated Destination: = Original
Translated Service: = Original
Reply With Quote
  #3 (permalink)  
Old 2007-03-29
Junior Member
 
Join Date: 2006-06-05
Posts: 6
Rep Power: 0
fabwhack has an average reputation (10+)
Default Re: Static NAT to SMTP server

I didn't (thought it might do that automatically, but I can see why it wouldn't), but I've added that in and I still can't connect to port 25 on the public address :(

NAT rules now look like:

any - public IP - smtp / original - private IP - original
private IP - any - smtp / public IP - original - original

I've got corresponding security rules too:

any - public IP - smtp
public IP - any - smtp
any - private IP - smtp
private IP - any - smtp

(I know eventually I'll only need two of the above, but this is just for testing).
Reply With Quote
  #4 (permalink)  
Old 2007-03-29
Senior Member
 
Join Date: 2006-06-28
Posts: 140
Rep Power: 3
david has an average reputation (10+)
Default Re: Static NAT to SMTP server

what do you see in the fw logs? (make sure that under query properties you have xlatesrc/xlatedst enabled.)
Reply With Quote
  #5 (permalink)  
Old 2007-03-29
Junior Member
 
Join Date: 2006-06-05
Posts: 6
Rep Power: 0
fabwhack has an average reputation (10+)
Default Re: Static NAT to SMTP server

That's the strange thing.

If I telnet out to port 25 somewhere from the mail server, everything is fine, and I can get a connection, and I can see the entry in the logs: the Xlatesrc is correct etc.

But connecting to port 25 from the outside world to the public address shows nothing in the logs! I've tried several different addresses, including ones that has being automatically NAT'd previously, and it's just not working :(
Reply With Quote
  #6 (permalink)  
Old 2007-04-07
Junior Member
 
Join Date: 2007-01-21
Posts: 20
Rep Power: 0
dfwboiler has an average reputation (10+)
Default Re: Static NAT to SMTP server

As someone else said, does Tracker show the nat translation happening?
Did you do an fw monitor to view traffic?

Does the smtp server have a route for the source?

"connecting to port 25 from the outside world to the public address shows nothing in the logs!"
Assuming your rule is logging, this sounds like a routing problem, not a fw problem.

Last edited by dfwboiler; 2007-04-07 at 14:50.
Reply With Quote
  #7 (permalink)  
Old 2007-04-07
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Static NAT to SMTP server

Did you set up proxy arp? When using manual NAT, the firewall cannot automatically add the proxy arp entry. You might want to try and use automatic NAT and see if it works.
Reply With Quote
  #8 (permalink)  
Old 2007-04-10
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Static NAT to SMTP server

Like chillyjim says, no logs in the firewall means packets aren't getting there, which in turn suggests that the firewall isn't replying to ARP for the public IP.

Unless you have a complex setup, automatic NAT is a much easier and elegant way to solve this.

My suggestion:
- Change the SMTP inbound rule to use the private IP object
- Delete the manual NAT rule and the Public IP object
- Add automatic address translation to the private IP object (edit it and go to the NAT tab, select automatic address translation, enter the public IP and chose "Static")
- Push the policy

That should be it.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:48.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0