CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-04
gluperini gluperini is offline
Junior Member
 
Join Date: 2007-01-16
Posts: 12
Rep Power: 0
gluperini has an average reputation (10+)
Default Manual NAT option : translate client side

Hi,

I'm having trouble using Manual NAT.
To let you know my problem, have look to my architecture (picture below).

- I've two firewalls managed with a Provider-1.
- One is directly connected to the LAN, the other one is connected to the LAN through the first one via a VPN connection.
- So 1 FW is managed using LAN and the other one is managed through internet connection
- The connection between that FW and the Provider-1 is OK.
- I use Manual NAT to allow the FW to comunicate with the ptovider-1 through internet.

I've some problem with NAT configuration with the FW managed throught internet and I need to change disable Manual NAT client side in the global policy settings to make it working.

I have manual NAT apply to the FW like :
From FW to Povider(@IP private) --NAT--> From FW to Provider(@IP public)

Actually, regarding the FW, If I keep the Manual NAT translate in client side I should have :

i : @IP Provideer-1 src = @IP dst (Private)
I : @IP Provideer-1 src = @IP dst (Public)
ROUTING
o : @IP Provideer-1 src = @IP dst (Public)
O : @IP Provideer-1 src = @IP privée (Public)

But the thing is with this configuration, Fw could not reach the Provider-1 through internet and when I check logs using the Smartview tracker, I can see that NAT hasn't occurs and the communication from the FW to the provider-1 is not NATed

If I do it another way (disabling the Manual NAT configuration into the global properties configuration).
It should be like this :
i : @IP Provideer-1 src = @IP dst (Private)
I : @IP Provideer-1 src = @IP dst (Private)
ROUTING
o : @IP Provideer-1 src = @IP dst (Private)
O : @IP Provideer-1 src = @IP privée (Public)

And this configuration should not work!
But this one is working and I can check that NAT is done (using the smartview tracker).

So I don't understand why is that working, whereas it should no works.
and why using Manut NAT translate client side doesn't work whereas it should work?

As I do not want to change global properties each time I push security policy on the FW, I would like to solve this issue differently or to at least to understand.


Thanks so much for your help.

regards
Attached Images
File Type: jpg CUPG.jpg (34.0 KB, 184 views)
Reply With Quote
  #2 (permalink)  
Old 2008-03-12
Brentd Brentd is offline
Member
 
Join Date: 2006-09-25
Posts: 42
Rep Power: 0
Brentd has an average reputation (10+)
Default Re: Manual NAT option : translate client side

I am not sure if I understand your problem, but from what I understand the client (or server) side natting is for destination NAT and not source NAT, as far as I know sourceNAT is always done on the server side???. So if you were doing client side destination NAT and source NAT then it would happen like this, from what I can remember, i, I, DestNAT, OS route ,SourceNAT o, O . Although you have not asked for twiceNAT (or Double NAT) I hope you can see what I mean..

When you run fw monitor use the -i option to track each interface one at a time and see if you then understand what I mean. I do think you have the wrong idea with client side NAT, is client side for "DEST NAT"

Can someone please confirm this to be factual!!

Brent
Reply With Quote
  #3 (permalink)  
Old 2008-03-12
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Manual NAT option : translate client side

Not sure about Provider-1, but in normal SmartCenter, when I have similar problems, I just create an object for the SmartCenter's public IP and then add that in the management tab of the firewall, rather than the one with private IPs. Then I only need NAT on the firewall close to the SmartCenter, rather than in both sides.

You can change this in:
Firewall object->Logs and Masters->Masters

Just add the public IP and move it to the top. Later you may want to remove the private IP.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:51.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0