CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-18
ttpm123 ttpm123 is offline
Junior Member
 
Join Date: 2007-02-16
Posts: 21
Rep Power: 0
ttpm123 has an average reputation (10+)
Default 'Reliable' NAT failing

A NAT technique I have used successfully is suddenly failing and I cannot find the loose thread.

DMZ servers use RFC 1918 space.
DMZ servers are static NAT'd to addresses in a public subnet for this purpose.

The NAT rule translates traffic from a vendor's four /25 addresses between the server's public and private IPs.

Policy restricts ports.

This has worked many times until now. Logs show the vendor hitting the public address and being dropped on the cleanup rule. XlateScr and XlateDst are null. This is why I think NAT is failing for some reason.

I cannot see why this is failing and appreciate any assistance.
Reply With Quote
  #2 (permalink)  
Old 2008-04-19
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 254
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: 'Reliable' NAT failing

hi mate before the cleanup rules do u have the rules to permit the traffic from the internet to ur dmz servers.do enable logging on those rules and check are u getting any hitcounts.

let us know would like to help u out.

regards

sebastan
Reply With Quote
  #3 (permalink)  
Old 2008-04-19
ttpm123 ttpm123 is offline
Junior Member
 
Join Date: 2007-02-16
Posts: 21
Rep Power: 0
ttpm123 has an average reputation (10+)
Default Re: 'Reliable' NAT failing

Yes, a rule is in place to allow traffic from the vendors subnets on defined ports to the RFC 1918 addresses for the servers.

The NAT rule is also defined; traffic sourced from Vendors subnets to the routable NAT address object is translated to the internal address object (static). I create an object for each hosts NAT address. I know there are other ways to do this, but I inherited this system and am continuing it while I plan an upgrade.


The logs show vendor hosts trying to reach the NAT addresses on allowed ports but being dropped on the cleanup rule. Logs entries are null for NAT'g.

I appreciate the help.
Reply With Quote
  #4 (permalink)  
Old 2008-04-19
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 254
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: 'Reliable' NAT failing

mate since u have statically translated the internal dmz server to the routable ip address. try in ur policy to permit traffic to the routable address of the servers than the internal server address.

let me know if that works.

regards

sebastan
Reply With Quote
  #5 (permalink)  
Old 2008-04-19
ttpm123 ttpm123 is offline
Junior Member
 
Join Date: 2007-02-16
Posts: 21
Rep Power: 0
ttpm123 has an average reputation (10+)
Default Re: 'Reliable' NAT failing

Bingo! That worked.

I looked through the rule base for traffic between the same internal and NAT subnets and see rules (and traffic) with and without the NAT object included in the policy. Is this a bug or something I've missed?

Thank you very much for your help. I've got the systems boys off my back!
Reply With Quote
  #6 (permalink)  
Old 2008-04-19
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 254
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: 'Reliable' NAT failing

hey great that thing worked.

even with static nat we can still have rules to reach the internal ip directly. but generally we do static nat for hiding our internal server;s ip address on the internet.

previously why it did;t work i guess cause u are using private addresses on the internal dmz servers.i guess on the outside router u are not having a route for internal addresses space pointing to the external interface of the gateway.

regards

sebastan
Reply With Quote
  #7 (permalink)  
Old 2008-04-19
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 323
Rep Power: 1
Thorpuse has an average reputation (10+)
Default Re: 'Reliable' NAT failing

Check which interface was generating the logging error. Also, may be worth logging implied rules and seeing if there's an anti-spoofing issue.
Reply With Quote
  #8 (permalink)  
Old 2008-04-21
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 346
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: 'Reliable' NAT failing

This is why I use automatic static NAT 99% of the time. You get both IPs assigned to a single object, making it cleaner and easier to manage/configure.

This also works for networks/subnets, just use the first IP (usually .0) and it will statically NAT all the range.
Reply With Quote
  #9 (permalink)  
Old 2008-04-22
ttpm123 ttpm123 is offline
Junior Member
 
Join Date: 2007-02-16
Posts: 21
Rep Power: 0
ttpm123 has an average reputation (10+)
Default Re: 'Reliable' NAT failing

This suggestion is what I am going to move forward on. It seems to have the benefit of simplicity. I am not sure why the previous admin defined 2 nodes for each server to implement NAT'g. Thanks for the push.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:18.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0