CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-17
sujithka sujithka is offline
Junior Member
 
Join Date: 2006-11-18
Posts: 6
Rep Power: 0
sujithka has an average reputation (10+)
Default NAT preference

Hi,

I have a small doubt. As all of us know we have two types of NAT in CP. One is manual ad the othre automatic. My question is that when we have both the kinds of NAT configured for an object, which NAT type will take preference.Or will the CP throw up an error message when we try to do the same.

Regards,
Sujith
Reply With Quote
  #2 (permalink)  
Old 2007-10-18
gavvys gavvys is offline
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 141
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: NAT preference

Hi
Well you can create the manual and automatic NATTING of a object, but it will come into picture when rules are folllowed, whichever rule comes first will be executed.The rules are followed from top to bottom.

I hope your query is resolved, if you have any issue please let me know.

regards
Ranjit
Reply With Quote
  #3 (permalink)  
Old 2008-02-15
chrissamuel chrissamuel is offline
Junior Member
 
Join Date: 2007-09-20
Posts: 8
Rep Power: 0
chrissamuel has an average reputation (10+)
Default Re: NAT preference

Automatic NAT rules take precedence as they appear at the start of the rulebase, not sure why you would want automatic and manual on the same object, you need to use manual really if you want to make use of bidirectional NAT.
Reply With Quote
  #4 (permalink)  
Old 2008-02-15
eduardw eduardw is offline
Member
 
Join Date: 2007-08-04
Posts: 53
Rep Power: 2
eduardw has an average reputation (10+)
Default Re: NAT preference

Quote:
Originally Posted by chrissamuel View Post
Automatic NAT rules take precedence as they appear at the start of the rulebase, not sure why you would want automatic and manual on the same object, you need to use manual really if you want to make use of bidirectional NAT.
That is not entirely true you can move the manual nat rules in front of the automatic rules. Use the add new rule on top and then move al the manual rules above the automatic rules. One of the reasons to use both is that you can use manual rules so that not al traffic will be translated.
With manual nat rules the order of the rules is important first matching rule will be applied for automatic nat rules the whole policy is used


Eduard
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:25.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0