Firewall-on-a-stick (with NAT)? Would it be possible to use the firewall merely as a routing/natting device, with policy-rules to regulate traffic? The problem is this: We have a firewall-cluster with one subnet to connect partner-networks. This subnet is divided in private VLAN's on the (Cisco) access-switches. We want to connect a new partner (partnerA), to give it access to a server. The problem is, that this server is still located at partnerB, and NAT has to be used. This server will be at our location in the near future and then this issue will be resolved, but in the mean time we're kinda stuck with this. The NATting will be done by the firewalls (R55), and it also has to route the packets. With this setup, there is only one interface used (the external one), because of the private VLAN-setup. Does Checkpoint have the ability to do this, or would it be easier to connect PartnerA to a separate interface during this transition-period? Any help would be appreciated... |