Does NAT function differently on Nokia platform? Sometimes on an IPSO platform, FireWall-1 will route before address translation occurs in 4.1 or in NG when the "Translate destination on client side" option is checked.
You have uncovered an idiosyncrasy of NAT on the Nokia platform. Check Point did not mean for it to happen this way, it is just how the code works out on Nokia. NAT is sometimes done by the time the packet is routed by the OS. Note that this is only on the Nokia platform and has not proven 100% reliable. You should still add the necessary static route or check the "Translate Destination on client side" checkbox to insure that it does work 100% of the time.
--
PhoneBoy - 01 Jan 2004
FAQForm FAQs.Class:
NetworkAddressTranslationFAQs,
TroubleshootingFAQs FAQs.OS:
OsNokiaIPSO FAQs.Version: