CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-19
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 254
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default urgent help required on this manual static nat pls

hi am i am having NGXR65 and i have configured manual static nat .

i have a policy permitting telnet traffic from any to the static nat address.

in my global properties i have enabled manual nat rules
translate destination on client side.

my internal host is 10.1.1.254 and my static nat address is 60.1.1.1.
my external host is 1.1.1.2 and firewall internal interface
firewall internal interface ip address is 10.1.1.100
firewall external interface ip address is 1.1.1.1

both the internal host and the external host are cisco routers. .

on firewall i have a default route pointing to the external host.

here;s are my nat rules.

rule 1

in the original packet
source inside-host(10.1.1.254) destination any service any

in the translated packet
source static-host(60.1.1.1) destination any service any

rule2

in the translated packet
destination statichost(60.1.1.1) source any service any

in the original packet
destination insidehost(10.1.1.254) source any service any

in the global properties nat page i have enabled i manual nat rules
translate destination on client side.

in the security rulebase i have added a rule to permit any to static-host telnet.

on the outside router i am having a route for 60.1.1.1 pointing to the external interface of the firewall.

i guess with these routes and since the static nat address is not in the same subnet of the external interface of the firewall i will not be needing any proxy arp entries on the firewall right.

cause when the cisco router does a AND operation for 60.1.1.1 it sees it has got a route so it will directly send it to the external interface of the firewall.

but still from past 2 days i am working out on this and not able to reach the internal host from the external host.


can someone pls help me out. i am really having a tuff time with this.

regards

sebastan
Reply With Quote
  #2 (permalink)  
Old 2008-04-19
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 862
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: urgent help required on this manual static nat pls

Why can't you use an automatic NAT rule?

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-04-19
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 254
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: urgent help required on this manual static nat pls

hi mate i am learning checkpoint. i have tried with auto-static nat and it works perfectly fine.

i am now trying to work on manual nat.

with manual nat i can send traffic from the internal host to the external host and it works fine.

the problem i am facing is traffic from the external host to the internal host.

if u can help me out or atleast help me in figuring out where i am going wrong. cause i am sure what i am trying to do is not very complicated.

regards

sebastan
Reply With Quote
  #4 (permalink)  
Old 2008-04-19
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: urgent help required on this manual static nat pls

you need to do this in NAT rule:

rule 1:

in the original packet
source inside-host(10.1.1.254) destination any service any

in the translated packet
source static-host(60.1.1.1) destination any service any

rule 2:

in the original packet
source any destination is static-host 60.1.1.1 service any

in the translated packet
source any destination inside-host 10.1.1.254 service any


in the security rule:

source is Any, destination is static-host 60.1.1.1 service is telnet.

I just tried on my Nokia firewall R55 and it works just fine.


Think about it, when host 1.1.1.2 wants to talk to host 60.1.1.1, since
you already have the route in place, source will be "ANY", for simplicity,
destination is 60.1.1.1 for original packet. For translated packet, you
want to keep the source the same but change the destination to
10.1.1.254. That's it.
Reply With Quote
  #5 (permalink)  
Old 2008-04-20
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 254
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: urgent help required on this manual static nat pls

mate thanks a million for helping me out. i am gonna try it out right now and i am pretty sure it will work. the logic u said is perfectly fine.

i am really amazed why there is not a single configuration example of manual static nat anywhere in the checkpoint documentation.

even in the checkpoint press NGX1 they have only mentioned automatic nat.

thanks a lot once again.

i am trying it now and will let u know soon.

regards

sebastan
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 19:23.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0