CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-03
Junior Member
 
Join Date: 2006-10-06
Posts: 8
Rep Power: 0
pinoo has an average reputation (10+)
Default Source Port NATing

Can you modify the src port on a Check Point GW, so that any traffic say from src A to dst B on port 23, will be seen by the destination B server as always coming from src port 5000 from A? So essentially, I want to perform src port NATing.

Is this at all possible, and if so, how is this performed?

Thanks!
Reply With Quote
  #2 (permalink)  
Old 2007-11-04
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 146
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: Source Port NATing

Hi
Yes that is possible in Checkpoint.
You can NAT anything, whether its port or IP, In the NAT traversal you can make the NATing rules there.

I hope you are clear with steps.
Reagrds
Ranjit
Reply With Quote
  #3 (permalink)  
Old 2007-11-05
Junior Member
 
Join Date: 2006-10-06
Posts: 8
Rep Power: 0
pinoo has an average reputation (10+)
Default Re: Source Port NATing

well no that is why i asked - what steps are required to have this working as i described above? the issue here is performing source port nating, not destination port so it's non-standard.

As i have smtp port object already defined, do i have to create a new smtp object and go to advanced settings and set the source port option to my defined port, then use this object in the translated service object field in the address translation tab?

if not please explain how to do this. i'm sure other will find this useful.

Last edited by pinoo; 2007-11-05 at 02:59.
Reply With Quote
  #4 (permalink)  
Old 2007-11-05
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Source Port NATing

You have to write the NAT rule manually rather then relying on the AutoNAT rules.

In the Address Translation section all that you do is specify the source and destination, along with the service coloum and then specify the xlate src that you want to see it leaving on, keep the destination as original and then set the xlate service to be tcp5000. You may need to define the xlate service.
Reply With Quote
  #5 (permalink)  
Old 2007-11-05
Junior Member
 
Join Date: 2006-10-06
Posts: 8
Rep Power: 0
pinoo has an average reputation (10+)
Default Re: Source Port NATing

But that would translate the destination port, not the actual source port that i want to see the traffic coming from
Reply With Quote
  #6 (permalink)  
Old 2007-11-05
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Source Port NATing

You will have SrcA to DstB on port 23 leaving the client.

At the gateway it will nat the SrcA to a public Address so can route across the Internet. It then xlates the service to port 5000 so that DstB sees the traffic arrive on port5000.

If this isn't what talking about then what are you talking about trying to do. Are you trying to say that the telnet leaves so that it arrives on port23 to a telnet server but is seen coming form port5000.

You won't get that to happen, plus wouldn't it break the service you are trying to use.
Reply With Quote
  #7 (permalink)  
Old 2007-11-05
Junior Member
 
Join Date: 2006-10-06
Posts: 8
Rep Power: 0
pinoo has an average reputation (10+)
Default Re: Source Port NATing

"telnet leaves so that it arrives on port23 to a telnet server but is seen coming form port5000." - yes this is exactly what im referring to. A weird application we're using requires that the source port for traffic is seen coming from say port 5000. So the requirement is to allow traffic from srcA destined to destB so that the src port appears as 5000. Is this at all possible on checkpoint?
Reply With Quote
  #8 (permalink)  
Old 2007-11-05
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Source Port NATing

AFAIK you can't change the source port, only the destination port.
Reply With Quote
  #9 (permalink)  
Old 2007-11-05
Senior Member
 
Join Date: 2007-06-04
Posts: 1,073
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Source Port NATing

If they run a weird requirement like that then why don't they supply a telnet client so that this is done automatically at the client, ie the client send with a src port of 5000 and dst of 23
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:52.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0