CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-14
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 254
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default help in understanding hide nat pls newbie

hi all i am new to checkpoint and am trying to figure out the working of nat . i am finding it pretty confusing.

in the global properties almost all of the nat tabs are selected .so even though nat is enabled in the global properties i checked that there is no nat happening
is it because i have not created the automatic nat rule in the network or the node object.

can someone pls tell me the importance of having the nat tabs checked in the global properties.

any help would be really great.

thanks

regards

sebastan
Reply With Quote
  #2 (permalink)  
Old 2008-04-15
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 434
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: help in understanding hide nat pls newbie

Hi,

NAT (static or hide) is not defined in the global properties.

NAT is defined on:

1) Either the actual network object (host object, network etc). Edit the object and you will see NAT tab where you can configure static or hide nat for the object

2) You can also do NAT manually, and you do that in Address Translation policy (Tab after security policy).
Reply With Quote
  #3 (permalink)  
Old 2008-04-15
coldark coldark is offline
Member
 
Join Date: 2006-08-30
Location: Cheshire UK
Posts: 32
Rep Power: 0
coldark has an average reputation (10+)
Default Re: help in understanding hide nat pls newbie

whoa - that is a BIG ask - and would take a long time to answer satisfactorily ;-)

But a few pointers to get you in the right direction.
1) The selections in the Global Properties Menu > NAT tab merely modify the way that FW1 does some of it's NAT BUT ONLY if you have configured NAT in the ways that Abusharif has mentioned.
2) You can configure (Automatic) NAT on objects by selecting the NAT Tab of that particular object - for HIDE NAT this would often be an internal Network Object - Automatic NAT Rules are "automatically" added to the NAT Tab of the rulebase.
3) Alternatively you can also configure (Manual) NAT, which would involve creation of an object to represent the NAT Address, then you "Manually" add rules to the NAT TAB of the rulebase.

There are many CheckPoint PDF's freely available but one of these "CheckPoint_NGX_Firewall_SmartDefense_User_Guide.p df", has a reasonable chapter on NAT.

These PDF's can be found either,
1) on the CheckPoint Installation CD - in the Docs folder.
2) on the CheckPoint website - Linked Here - this requires registration on the site.

If you have no joy, then I could email you a copy, but its a 10MB fpdf.

If you are considering doing a CheckPoint course, (Automatic) NAT, Hide and Static, is fully covered on the CheckPoint NGX1 course, Manual NAT is briefly covered. I have a PPT slide sequence on this subject from when I teach it - it is fairly scant, as it's usually used in conjunction with me teaching the subject ;-) you are welcome to a copy of that too if you like - but I wont be able to get hold of that until a bit later in the week.
Reply With Quote
  #4 (permalink)  
Old 2008-04-15
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 254
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: help in understanding hide nat pls newbie

thanks a lot man i got it thanks.

regards

sebastan
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 09:47.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0