CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-03-19
vvcat vvcat is offline
Junior Member
 
Join Date: 2008-01-30
Posts: 27
Rep Power: 0
vvcat has an average reputation (10+)
Default Pls share your experience

Hi all,

just share your experience, I think should not a problem

CASE 1

firewall have 3 segment
DMZ 192.160.2.x
LAN 192.160.3.x
WAN 202.x.x.x

webserver was put on DMZ e.g. IP is 192.160.2.4 NAT 202.32.33.8 (one-to-one NAT)
email server put on LAN e.g. IP is 192.160.3.4 NAT 202.32.33.9 (one-to-one NAT)

suppose LAN PC can only ping 192.160.2.4 and 192.160.3.4, but actually LAN PCs can ping 202.32.33.8 and 9, is it normal on checkpoint firewall?

we use sonicwall and netscreen before, but cannot ping NAT true IP except the whole LAN zone is a true IP.
Reply With Quote
  #2 (permalink)  
Old 2008-03-19
RedKnot RedKnot is offline
Junior Member
 
Join Date: 2008-01-31
Posts: 3
Rep Power: 0
RedKnot has an average reputation (10+)
Default Re: Pls share your experience

Hey Dude,

I believe the NAT ping feature is most likely because there is a rule that permits the LAN segment to ping the NAT'ed address. I'd suggest that you check tracker.
Reply With Quote
  #3 (permalink)  
Old 2008-03-19
vvcat vvcat is offline
Junior Member
 
Join Date: 2008-01-30
Posts: 27
Rep Power: 0
vvcat has an average reputation (10+)
Default Re: Pls share your experience

Not only for ping issue, I open the broswer from the LAN PC and type http://<NAT IP> is also ok! Not just for 192.xx.x.x
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 13:07.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0