CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-09
djash djash is offline
Junior Member
 
Join Date: 2007-01-09
Posts: 2
Rep Power: 0
djash has an average reputation (10+)
Default 2 IP addresses, one physical using Nokia and CP R60

All, I have the following problem:

My customer is using 2 Nokia 390 boxes and Checkpoint R60. They have a connection to the Internet via an ISP managed router. The routing on this is all done via the following subnet and IP addresses:

Nokia1: 213.86.16.251/29
Nokia2: 213.86.16.252/29
NokiaVRRP: 213.86.16.250/29

RouterIP: 213.86.16.253/29

Which is all fine and functions OK. However, the customer has a new requirement to have static NATs configured for several new services, and in planning for this has obtained a new range of public IP addresses from the ISP: 80.169.199.x/24 as the previous range does not give enough IP addresses.

Now the Nokia boxes have a 2nd IP address configured on the interfaces within this range:

Nokia1: 80.169.199.251
Nokia2: 80.169.199.252

, but the Internet router does not, but it does have a route for this network pointing to the Nokia and is advertising this out to the Internet.

The problem is that Checkpoint does not recognise these 2 IP addresses in it's Topology information and my customer would like to use this range for static NAT. The quesiton I have is, is this possible? and if so how? If anybody has any experience of this it would be much appreciated.
Reply With Quote
  #2 (permalink)  
Old 2007-06-14
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 983
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: 2 IP addresses, one physical using Nokia and CP R60

If the ISP Router is forwarding the traffic to your Nokia VRRP address for the first IP range then this should work fine. Just define your static NAT as per normal and use the new IP range.

I have done this myself where I had a similar situation for a customer.
Reply With Quote
  #3 (permalink)  
Old 2007-06-14
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: 2 IP addresses, one physical using Nokia and CP R60

You'll need to create the proxy arp with the VRRP MAC though right?
Reply With Quote
  #4 (permalink)  
Old 2007-06-15
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 983
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: 2 IP addresses, one physical using Nokia and CP R60

I didn't have too as the Router was sending the traffic to the Nokia anyway so no need for the router to ARP and require proxy arp to be configured on the Nokia.

The Nokia just recieves the packets as they are routed to it.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:57.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0