CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-12-15
Junior Member
 
Join Date: 2005-12-11
Posts: 2
Rep Power: 0
sbertrand has an average reputation (10+)
Default NAT with cluster-Host without Hide mode

Hi,

Here's the architecture:

[My_Server]------|my Fw CP|----link---|External Fw|---- [external-Host]

[My_Server] = 10.3.5.10

[My NATed Server] (by my Fw CP) = 10.33.55.10

[My_server]is seeing by [External Host] with the NATed address: 10.33.55.10

[External Host] is in fact a pool of clustered machines.

10.220.80.20 is the Master (it's only Listening) then,
10.220.80.19 (is a set of machine that sends packets over the network, a cluster member1)
10.220.80.18 (is a set of machine that sends packets over the network, a cluster member2)
10.220.80.17 (is a set of machine that sends packets over the network, a cluster member3)

[External Host]= (10.220.80.20) is NATed with [my Fw CP] as follow: 10.30.12.3

So... Here's the problem:

1- My Server (10.3.5.10) iniate a connection to the external Host,
2- The Fw CP, NAT the source address (10.3.5.10) to (10.33.55.10) and foward to the external listening Server (10.30.12.3)
3- Then, the [External Server] accept connection, BUT reply randomly (load balancing) with A cluster members:
10.220.80.18,
10.220.80.19,
10.220.80.17.

=> So the session opened in [my Fw CP] (the initate connection from my server)
has not the same destination Address when a cluster External Host is replying!

Note: The [external Fw] is unable to process NAT HIDE with External-Host,
anyway as long as [My_server] is initiating connection, hyde mode is not possible !!!

??? The Question is ???
=> How [my Fw CP] could match the reply connection (in his session table),
assume that the [external cluster machine] that is responding is different from the listening one?

Get it?
Thanks a million,
Steven
Reply With Quote
  #2 (permalink)  
Old 2005-12-18
Junior Member
 
Join Date: 2005-12-02
Location: France
Posts: 27
Rep Power: 0
Peter has an average reputation (10+)
Default Re: NAT with cluster-Host without Hide mode

One need to know how does the cluster work. Normally, if you have an TCP connexion to one host you cannot receive the answer from another host (you have no any TCP connexion between your station and the second host!). So you should understand the details of redirection in claster. Right know I don't understand how can it work...
Reply With Quote
  #3 (permalink)  
Old 2005-12-19
Junior Member
 
Join Date: 2005-12-11
Posts: 2
Rep Power: 0
sbertrand has an average reputation (10+)
Default Re: NAT with cluster-Host without Hide mode

Thanks for responding,

I am agree with you.
I think it 's not possible to deal with this kind of problem.
I 'll close this post soon :(
shusss...
Reply With Quote
  #4 (permalink)  
Old 2006-03-14
Junior Member
 
Join Date: 2006-02-28
Posts: 5
Rep Power: 0
johngwyn has an average reputation (10+)
Default Re: NAT with cluster-Host without Hide mode

In this situation I usually setup a loopback interface on the load balanced hosts with the load balanced address on it and use it to reply with OR send the traffic back to the load balancer device to be NATted back
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:37.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0