CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-10-28
Junior Member
 
Join Date: 2005-10-28
Posts: 8
Rep Power: 0
Dj_Lien has an average reputation (10+)
Default NAT Question....

My company has a two legal IP address. I want to run a webserver (and a few other servers) behind one of these address.

I found this
http://www.phoneboy.com/bin/view.pl/...ranslationFAQs
http://www.phoneboy.com/bin/view.pl/...ksInFireWallNG

But still can't seem to get NAT (or is that work out lol ) working on our Firewall. I've included a few screen grabs.

With this setting for the object


& these are is the rules I've tried. But it don't seem to work.



&



Im running NG FP3 R55. Any help before I start diging into manuals......

Last edited by Dj_Lien; 2005-10-28 at 08:02.
Reply With Quote
  #2 (permalink)  
Old 2005-10-28
Junior Member
 
Join Date: 2005-10-27
Posts: 5
Rep Power: 0
charlesdf23 has an average reputation (10+)
Default Re: NAT Question....

If you want external people to access this server, you need to set static and put a routable IP address in the field.
Reply With Quote
  #3 (permalink)  
Old 2005-10-28
Junior Member
 
Join Date: 2005-10-28
Posts: 8
Rep Power: 0
Dj_Lien has an average reputation (10+)
Default Re: NAT Question....

Quote:
Originally Posted by charlesdf23
If you want external people to access this server, you need to set static and put a routable IP address in the field.
Thanks. I was close but no cigar.
Reply With Quote
  #4 (permalink)  
Old 2005-10-28
Junior Member
 
Join Date: 2005-10-27
Posts: 2
Rep Power: 0
phauser has an average reputation (10+)
Send a message via MSN to phauser
Default Re: NAT Question....

Quote:
Originally Posted by charlesdf23
If you want external people to access this server, you need to set static and put a routable IP address in the field.
OR.... Configure a NAT rule making PAT. Example: for accessing your webserver at TCP80, you should make a NAT redirecting all incoming traffic to FW host at TCP80, to your_webserver:80.
__________________
pH | http://www.securearg.net
Secure from the source
Reply With Quote
  #5 (permalink)  
Old 2005-10-31
Junior Member
 
Join Date: 2005-10-28
Posts: 8
Rep Power: 0
Dj_Lien has an average reputation (10+)
Default Re: NAT Question....

Quote:
Originally Posted by phauser
OR.... Configure a NAT rule making PAT. Example: for accessing your webserver at TCP80, you should make a NAT redirecting all incoming traffic to FW host at TCP80, to your_webserver:80.

Where can I get some documentaion on PAT? There is only NAT in the manual that came with NG. I will need to add a FTP server into the list. Can I just use the firewalls IP address as the 'hide behind address' & it will create PAT rules for me?

Thanks for your quick replys fellas. I owe you a beer or something :)
Reply With Quote
  #6 (permalink)  
Old 2005-10-31
Member
 
Join Date: 2005-10-25
Location: North Brunswick, NJ
Posts: 38
Rep Power: 0
czech12 has an average reputation (10+)
Default Re: NAT Question....

PAT is just a term that is used. It really means that you are configuring an address to be NAT'd only on a certain port. For instance, you can say:

Original Packet Source: Any
Original Packet Destination: Public IP for Web Server
Original Packet Service: HTTP

Translated Packet Source: Original
Translated Packet Destination: Static NAT to Web Server
Translated Packet Service: Original

The reason why you would want to do this is if you have many servers that need to use public IP addresses, you can use the same public address, but translate it to different servers based on the service being used.

I don't know if you'll find any real documentation on PAT, but hopefully that explains it for you.
__________________
====================
Aaron Vivo
CCSE Plus, CCMSE, NSA
====================
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:13.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0