CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDashboard
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-03
davegibelli davegibelli is offline
Junior Member
 
Join Date: 2007-11-05
Posts: 3
Rep Power: 0
davegibelli has an average reputation (10+)
Default Simple question

I want to search for NAT rules based on an IP address

E.G I have an address 51.0.0.2 that is being NATed to something on the inside but how do I figure out what it is being NATed to?
Reply With Quote
  #2 (permalink)  
Old 2007-12-03
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,027
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Simple question

If you have an object for the IP then just ricght click on the object select where used and it will tell you which NAT rules the object is used in.

You can then look at the NAT rule and see what being NATted too.

Alternatively you can expand the query properties in the TRacker and include NAT Rules and Src xlate and dst xlate coloumns to see what the IP is being translated too, by filtering for the IP address in the source coloumn
Reply With Quote
  #3 (permalink)  
Old 2007-12-03
davegibelli davegibelli is offline
Junior Member
 
Join Date: 2007-11-05
Posts: 3
Rep Power: 0
davegibelli has an average reputation (10+)
Default Re: Simple question

The problem is I cannot find the object...

All I know is the IP address, 51.0.0.2, is there a way to search for the IP address?
Reply With Quote
  #4 (permalink)  
Old 2007-12-04
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,027
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Simple question

In that case use the method I said using SMARTView Tracker and type the IP address as the dest. Expand the query properties so can see the xlate dst coloumn as well and this tells you the xlated dst that the IP is being translated too.

You are using the filtering capability in the logs so make sure you are logging your traffic.

If you also show the NAT Rule then you can see what rule this is being caught under.

This way it will just show traffic destined for 51.0.0.2, what the NAT rule being applied is and also what address it is being NATted too.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:43.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0