CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-10
TLS82 TLS82 is offline
Junior Member
 
Join Date: 2007-05-21
Posts: 3
Rep Power: 0
TLS82 has an average reputation (10+)
Default Public to private NAT

Hi,

I'm not very familiar with Checkpoint's innerworking (i'm more at ease in a Cisco environment) and I'm having some problems with a NAT configuration any help is appreciated. (I'll be getting some training on checkpoint in 2 months time)

In my current setup using a NGX65 HA cluster i have the DMZ with public adressing, my problem is i nedded a couple of servers to be able to contact servers on the internal WAN (they need routing to get to them).
I tried creating a manual hide rule, to NAT all these IPs behind a private IP when they try to contact the specified servers on the private network (the connections are always started by the servers on the DMZ), but the firewall is droping the the packet with info "message_info: Address spoofing", i have translate destination on client side selected on the global properties.
Any ideas on how to work around this? Would specifying NAT (static or hide)on the objects that represent the DMZ servers to a private IP just NAT the communications to the inside ?


Thanks,

Tiago
Reply With Quote
  #2 (permalink)  
Old 2008-03-10
mcnallym mcnallym is online now
Senior Member
 
Join Date: 2007-06-04
Posts: 1,027
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Public to private NAT

You will need to update the topology setting.
Reply With Quote
  #3 (permalink)  
Old 2008-03-10
TLS82 TLS82 is offline
Junior Member
 
Join Date: 2007-05-21
Posts: 3
Rep Power: 0
TLS82 has an average reputation (10+)
Default Re: Public to private NAT

How do I do that?

Thanks,

Tiago
Reply With Quote
  #4 (permalink)  
Old 2008-03-11
mcnallym mcnallym is online now
Senior Member
 
Join Date: 2007-06-04
Posts: 1,027
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Public to private NAT

Go into the Firewall Object

Select Topology

Locate the Get Interfaces and select Get Interfaces with Topology.

Accept the changes and install policy.
Reply With Quote
  #5 (permalink)  
Old 2008-03-12
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Public to private NAT

If you use automatic NAT (the NAT tab in the objects) this always leads to generic rules. In this case you need a specific rule for certain networks or objects.

From what you describe, NAT Hide is indeed the right choice:

Servers | Internal WAN | any | Hide IP | = | =

Then check the logs and see where it's being dropped. The logs will tell you which interface dropped the packets and why. Also if you check the Xlated Src and Xlated Dst you will be able to know if NAT has occurred and if its working properly.

Then you can adjust the anti-spoofing accordingly. By going to the topology TAB on the firewall object, as mcnallym said.

PS Are you Portuguese by any chance?
Reply With Quote
  #6 (permalink)  
Old 2008-03-14
TLS82 TLS82 is offline
Junior Member
 
Join Date: 2007-05-21
Posts: 3
Rep Power: 0
TLS82 has an average reputation (10+)
Default Re: Public to private NAT

Thanks mcnallym and MarioL, I've tried to update the topology but I still get the same results. Meanwhile I've disabled the anti-spoofing on the required interface to make it work for now, but I would still like to get it working properly :-)

I've logged the rule the allows the traffic through and what shows up in the logs is:
1st the packet being accepted on the correct interface
2nd, right below it the packet being denied on another interface (in this case the external interface that connects to the outside world).

What doesn't make any sense to me is why it's showing up as coming from the outside interface, i would think at most it woul appear as though it was coming from the interface where the network that contains the address it is being translated to is attached to... Any help on what could be going on is appreciated.

MarioL- how can I check the Xlated Src and Xlated Dst ?

Thanks,

Tiago

PS- MarioL - yes I am Portuguese, you too ?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:23.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0