CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-25
Wutkung Wutkung is offline
Member
 
Join Date: 2006-05-10
Posts: 32
Rep Power: 0
Wutkung has an average reputation (10+)
Default Hide NAT with Proxy-Arp Issue.

Recenty I create Security Policy + Manual NAT Policy like this

Security Policy :

From HostA / To HostB / Service Any / Accept / Log

NAT Policy :

From HostA / To HostB / Service Any / NATSrc HostA-NAT / Original / Original

After install security policy, I try to ping HostB from HostA but ping didn't work.

Then I tcpdump on outgoing interface and found that ping from HostA is arrive at HostB then HostB broadcast arp-request from HostA-NAT and no one reply to that question.

I type "fw ctl arp" and there is no Proxy-arp list here.

But when I change Manual NAT to Automatic NAT, It's work completely.

Suggestion please,

Edit: This Machine is CheckPoint NGX R60 with Enforcement Module + Smart Center Server on it and running on SecurePlatform.

Last edited by Wutkung; 2007-05-25 at 00:23.
Reply With Quote
  #2 (permalink)  
Old 2007-05-25
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 143
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: Hide NAT with Proxy-Arp Issue.

if you dont have proxy arp enabled for the interface and configured the /etc/ethers file there is no arp entry.

The simples solution to manage arp at the gateway on SPLAT is

# touch $FWDIR/conf/local.arp

file $FWDIR/conf/local.arp
---------------------------------
# proxy_arp_ip Interface_MAC Interface_real_IP


push the policy with manual nat rule and then take a look with fw ctl arp.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:48.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0