CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-21
bkeaver bkeaver is offline
Junior Member
 
Join Date: 2007-09-18
Posts: 8
Rep Power: 0
bkeaver has an average reputation (10+)
Default easy one guys

ok I have a VPN that I need to setup. This is probably so easy I am just totally missing it....

I need to setup the VPN so that all of my internal network is nat'd behind 1 external address....for some reason I am looking at this and its not clicking....

tried searching forum but couldnt find what I was looking for and I am sure the question has came up before...


thanks in advanced guys
Reply With Quote
  #2 (permalink)  
Old 2008-01-21
rokudan rokudan is offline
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: easy one guys

Not sure exactly what you are talking about, since your question could mean several things... But there are a few ways to NAT a network, depending on what your purpose is.. You can create a network object for your desired network, then on it's NAT tab do a hide.. Or if you want to be more specific for what destinations and/or services you want to NAT for, you could go to the Address Translation tab in SmartDashboard, and create a rule... Of course you will need to create and object for the hide as well.
Reply With Quote
  #3 (permalink)  
Old 2008-01-23
Testing-123 Testing-123 is offline
Member
 
Join Date: 2007-07-27
Posts: 89
Rep Power: 2
Testing-123 has an average reputation (10+)
Default Re: easy one guys

Hi bkeaver,

There are two form of NAT; static and hide.

You will need to use hid NAT by your description. Open up smart dashboard in demo mode and look at the example in the nat policy as it gives an example of all the different variations of NAT. It's difficult to help you unless we have a more detailed explantion.

Hope this helps.

Cheers
Testing-123
Reply With Quote
  #4 (permalink)  
Old 2008-01-28
bkeaver bkeaver is offline
Junior Member
 
Join Date: 2007-09-18
Posts: 8
Rep Power: 0
bkeaver has an average reputation (10+)
Default Re: easy one guys

what I am trying to accomplish is:

they have a FTP server that I need to access through a VPN but to avoid overlaping internal network IP's. We want to nat my entire internal network behind 1 external ip address. I have tried to do a automatic NAT with my existing network Object but when I ping thier FTP server it sends the packet through the tunnel as my internal netowork (10.1.0.0) instead of the outside IP (Lets say 64.64.64.64).

If I try to do a manual nat it tells me "The range size of Original and Translated columns must be the same."

original Packet | Translated Packet
source | destination | Source | destination
10.1.0.0 | thier FTP server |64.64.64.64| original
----------------------------------------------------------
FTP Srvr | 64.64.64.64 | Original | 10.1.0.0

hopefully this displays correctly and I have explained it clearly enough....Anyone????
Reply With Quote
  #5 (permalink)  
Old 2008-01-29
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: easy one guys

In terms you NAT you only need one rule:

LAN | FTP server | any | Hide IP | = | =

Hide IP should be an host object with the IP you want to hide behind. This object should be added on the rule with the option Hide NAT.

Of course you need to also worry about routing and possibly ARP, to make sure this IP "comes back" to your firewall.

You will need to make sure that the VPN isn't avoiding the NAT rules, so check the VPN community and make sure you haven't prevented NAT (basically untick that box).

Hope that works, let me know if you need anything else.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 10:51.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0