CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-14
sphinx sphinx is offline
Junior Member
 
Join Date: 2007-03-06
Posts: 8
Rep Power: 0
sphinx has an average reputation (10+)
Default NAT Question

Folks,

I own 30 public IP addresses 1.2.3.1 - 1.2.3.30 that are used for public access from the internet. Currently they are not in a DMZ but i would like to implement them into a DMZ, my question is can i create a NAT pool for these servers and still only use my one external interface on my checkpoint firewall and have it listen for the public addresses that are natted?

Thanks in advance for the help.
Reply With Quote
  #2 (permalink)  
Old 2007-05-15
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: NAT Question

NAT configuration can be very flexible. It's quite common for smaller customers to have all public IPs in the external interface of the firewall and then NAT the DMZ servers.

This is also very easy to configure, all you need to do is create automatic NAT for the servers that have public services that must be reachable from the outside.

Typically your NAT table should look something like:

All your nets | All your nets | any | = | = | = (Unless you want NAT between your nets)
automatic NAT rules here
Internal nets | any | any | Hide IP | = | =

The thing to bear in mind is that when you NAT the servers, internal access to them will need to use the public IP too, or you can create a "no NAT" rule like shown above.
Reply With Quote
  #3 (permalink)  
Old 2007-05-15
sphinx sphinx is offline
Junior Member
 
Join Date: 2007-03-06
Posts: 8
Rep Power: 0
sphinx has an average reputation (10+)
Default Re: NAT Question

Thanks for the insight i understand it better now thanks again
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:56.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0