CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-26
Junior Member
 
Join Date: 2007-08-15
Location: NL
Posts: 15
Rep Power: 0
Wullum has an average reputation (10+)
Default Hiding NAT excluded for some interfaces

Hi all,

got a hiding NAT issue on R65 FW1 with 3 interfaces used:

eth1 external to internet (public addresses)
eth2 internal to LAN (private addresses)
eth3 internal to DMZ (private addresses)

I use hiding NAT for my internal network to access internet. I hide my internal private network behind 1 public address.
I also tried to hide the internal private network behind the gateway (i.e. based on topology) for testing.

When I route traffic from the internal network 192.168.x.0 behind eth2 to a router behind eth3 in network 192.168.y.0 traffic arrives at the router with the public ip (NATted). This is while hiding behind 1 public address.
When i route traffic from the internal network 192.168.x.0 behind eth2 to a router behind eth3 in network 192.168.y.0 while hiding behind gateway, traffic arrives at the router with the eth3 interface private ip.

Although fully explainable (and by design I guess), this is not desired.

I only want hiding NAT to be applied to traffic going into the "external" internet interface eth1, not for traffic going into the DMZ interface eth3.

Is there a way of excluding interfaces from NAT being applied, to enble me to arrive with my private internal ip 192.168.x.a at router 192.168.y.b in the DMZ instead of with a NATted ip?


Thanks for replies I can solve this with.

Wim
Reply With Quote
  #2 (permalink)  
Old 2008-02-26
Senior Member
 
Join Date: 2006-09-26
Posts: 822
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: Hiding NAT excluded for some interfaces

Easy. Create a mannual NAT rule as follows and put it at the top of
the nat translation:

source destination service original
internal dmz any original
dmz internal any original

that will make traffic goes from internal to dmz and vice versa from not being
NAT'ed.
Reply With Quote
  #3 (permalink)  
Old 2008-02-26
Junior Member
 
Join Date: 2007-08-15
Location: NL
Posts: 15
Rep Power: 0
Wullum has an average reputation (10+)
Default Re: Hiding NAT excluded for some interfaces

Thx cciesec2006, I already did.

Tried to include these rules inbetween the automatic NAT rules, but SmartConsole won't let me, so I put them at the top.

Unfortunately I cant test this during business hours.....

W
Reply With Quote
  #4 (permalink)  
Old 2008-02-26
Senior Member
 
Join Date: 2007-07-16
Posts: 625
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Hiding NAT excluded for some interfaces

You want your "Anti-NAT" rules at the top of the Rulebase anyway - like the firewall policy, NAT rules are processed in order.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:38.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0