CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-04
antonyso88 antonyso88 is offline
Senior Member
 
Join Date: 2006-11-23
Posts: 151
Rep Power: 2
antonyso88 has an average reputation (10+)
Default Manual NAT to private network

Hi,

I am using R55P.

I need to do a manual Source NAT as my internal is conflict with the remote vendor network. Here is the draft connection.

Internal (10.0.0.X) - Checkpoint - External (192.168.0.X) - {Network Cloud} - Remote Vendor Network.

My 10.0.0.X is conflict with the remote vendor network. And they ask me to SNAT the 10.0.0.X to 172.0.0.X.

The question is can i use manual NAT to do it? I tried to do it but i can't add the proxy arp.

Any idea?
Reply With Quote
  #2 (permalink)  
Old 2008-05-05
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 254
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: Manual NAT to private network

hi yes can use manual nat. rather than adding proxy arp entries on the firewall add a route on the outside router for the natted address pointing to the external interface of the firewall.

hope this helps.

regards

sebastan
Reply With Quote
  #3 (permalink)  
Old 2008-05-05
Nisha George Nisha George is offline
Junior Member
 
Join Date: 2008-05-01
Posts: 2
Rep Power: 0
Nisha George has an average reputation (10+)
Default Re: Manual NAT to private network

Hi,
This question may not be related to this thread.. But im helpless to open a new thred.. so asking my question here..

Im configuring CP - NGX - R65

Do anyone know how and why 2 NAT rules are created when a network object is enabled with NAT(static or hide behind gateway or hide behind ip).
For ex., under network objects -> networks -> add network --> testing, 192.168.0.0 mask 255.255.255.0 and
NAT --> hide behind gateway.

Now in smart dashboard, 2 NAT rules are shown for the network object - > testing
NAT RULE 1 === 192.168.0.0 192.168.0.0 any original original original
NAT RULE 2 === 192.168.0.0 any any <hiden ip> original original

Could you please let me know how can we see all these installed NAT rules in MDS thru some opsec client tools?( Im trying to retrieve all the NAT rules thru opsec API's but NAT RULE 1 is not able to retrieve)

Plz reply me if you have any info..
Thanks a lot!
Reply With Quote
  #4 (permalink)  
Old 2008-05-05
vzxdyy vzxdyy is offline
Junior Member
 
Join Date: 2007-09-05
Posts: 3
Rep Power: 0
vzxdyy has an average reputation (10+)
Default Re: Manual NAT to private network

The first rule for an automatic nat rule is basically saying don't translate traffic destined for same network which is 192.168.0.0. 2nd rule is saying nat everything else as firewall gateway IP.
Reply With Quote
  #5 (permalink)  
Old 2008-05-05
antonyso88 antonyso88 is offline
Senior Member
 
Join Date: 2006-11-23
Posts: 151
Rep Power: 2
antonyso88 has an average reputation (10+)
Default Re: Manual NAT to private network

If i won't do the proxy arp in router, i use checkpoint to do it. Is it possible?
Reply With Quote
  #6 (permalink)  
Old 2008-05-06
sebastan_bach sebastan_bach is offline
Senior Member
 
Join Date: 2005-10-12
Posts: 254
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: Manual NAT to private network

yes it is possible by adding a arp entry in the checkpoint firewall for the natted address and the mac address of the external interace.

but generally poeple find it more easy of adding a route on the outside router for the natted address pointing to the external interface of the firewall as the next-hop.

regards

sebastan
Reply With Quote
  #7 (permalink)  
Old 2008-05-06
Nisha George Nisha George is offline
Junior Member
 
Join Date: 2008-05-01
Posts: 2
Rep Power: 0
Nisha George has an average reputation (10+)
Default Re: Manual NAT to private network

>>>>>>The first rule for an automatic nat rule is basically saying don't translate traffic destined for same network which is 192.168.0.0. 2nd rule is saying nat everything else as firewall gateway IP.

Now I understood the behavior of the first rule now!
1. But when i install these NAT rules on firewall, how to make sure that this rule and how many more rules are pushed into the specific firewall?
2. Im trying to get the NAT rules configured in checkpoint MDS thru opsec library, during that time the rule-1 is not returned by the checkpoint.
So it looks like a bug or any insight on this from your side?

Thanks a ton!
Reply With Quote
  #8 (permalink)  
Old 2008-05-07
antonyso88 antonyso88 is offline
Senior Member
 
Join Date: 2006-11-23
Posts: 151
Rep Power: 2
antonyso88 has an average reputation (10+)
Default Re: Manual NAT to private network

I tried to do the Manual NAT + proxy arp as mentioned. But it's not allowed in my nokia box when add the proxy arp. It said "The network segment is not exist"
Reply With Quote
  #9 (permalink)  
Old 2008-05-09
mkikuda mkikuda is offline
Junior Member
 
Join Date: 2007-09-21
Location: Brazil
Posts: 1
Rep Power: 0
mkikuda has an average reputation (10+)
Default Re: Manual NAT to private network

It seems that the IP address you're trying to proxy arp is not in the same subnet of the firewall interfaces.
Reply With Quote
  #10 (permalink)  
Old 2008-05-19
antonyso88 antonyso88 is offline
Senior Member
 
Join Date: 2006-11-23
Posts: 151
Rep Power: 2
antonyso88 has an average reputation (10+)
Default Re: Manual NAT to private network

That's exactly the subnet not in firewall. How can i solve it?
Reply With Quote
  #11 (permalink)  
Old 2008-05-19
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 857
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Manual NAT to private network

Add a secondary IP address in Voyager to the Nokia's external interface, and then use manual proxy arp.

This works for me.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 19:35.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0