CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-31
gfgkemp gfgkemp is offline
Junior Member
 
Join Date: 2006-12-15
Location: Guildford, Surrey. UK
Posts: 7
Rep Power: 0
gfgkemp has an average reputation (10+)
Default NATing Remote Desktop to multiple custom ports.

Hi, I’m having a problem NATing Remote Desktop through to custom ports. We have an IP390 with R62 at a remote location which is protecting a customer system. To manage the servers in the system we need to be able to connect with Microsoft Remote Desktop.

However, for security and because of a lack of available external public IP addresses at the remote location we want allow RDP access to multiple servers using one public IP address and multiple custom ports.

For example 100.0.0.1:8000 NATs to port 3389 on server A and 100.0.0.1:8001 NATs to port 3389 on server B.

I have two NAT rules setup for each server, one allows the initial connection and the other is the return rule as in the attached image but with a different custom port for each machine.

When this was first implemented connecting to the remote public IP and custom port worked and traffic could be seen in the logs. However, for some unknown reason the connection seems to have hung, no new connections could be made and the log on the firewall stopped reporting any of the expected entries and I don't even get any dropped packets being reported.

Has anyone come across this before or do I have a problem with the NAT rules?

Thanks

Graham
Attached Images
File Type: jpg NAT.JPG (28.5 KB, 104 views)

Last edited by gfgkemp; 2007-07-31 at 05:19. Reason: Check Point version
Reply With Quote
  #2 (permalink)  
Old 2007-07-31
nandushankar nandushankar is offline
Junior Member
 
Join Date: 2006-04-27
Posts: 14
Rep Power: 0
nandushankar has an average reputation (10+)
Default Re: NATing Remote Desktop to multiple custom ports.

Hi

any -> 100.0.0.1 -> 8000 Destination:A -> service 3389

A > any -> 3389 -> original -> original -> service 8000

Please try this and get back
__________________
Nandu Shankar
CCSA,CCSE,CCSE+,CCMSE,RHCE,CCNA,MCP
Reply With Quote
  #3 (permalink)  
Old 2007-08-15
gfgkemp gfgkemp is offline
Junior Member
 
Join Date: 2006-12-15
Location: Guildford, Surrey. UK
Posts: 7
Rep Power: 0
gfgkemp has an average reputation (10+)
Default Re: NATing Remote Desktop to multiple custom ports.

Thanks for the reply. Unfortunately I have the translations working on one of the firewalls I manage the original way I put in my post. For some unknown reason both this way and the method you suggested do not work on the new system I’ve just configured.

What i'm seeing is, with the translated ports i can make one sucessful connection then nothing, I don't even get any dropped packets.
Reply With Quote
  #4 (permalink)  
Old 2007-12-18
gfgkemp gfgkemp is offline
Junior Member
 
Join Date: 2006-12-15
Location: Guildford, Surrey. UK
Posts: 7
Rep Power: 0
gfgkemp has an average reputation (10+)
Default Re: NATing Remote Desktop to multiple custom ports.

This was resolved by configuring the proxy ARP address on the Nokia Voyager for the external IP i wanted to NAT multiple ports for.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:29.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0