?
Solved

Checkpoint NAT issue

Posted on 2005-03-11
7
Medium Priority
?
936 Views
Last Modified: 2013-11-16
I have a Checkpoint NG fwall and another trusted site is attempting to communicate with one of my internal servers over the internet. The internal server's internal IP 192.168.1.2 is natted to an internet IP. When a tracert is performed from the trusted site to the server's internet ip, it arrives through the CP fwall fine. However the the reply to the source from the fwall is not retranslated back to the internet IP..Instead it's a non routable ip...192.168.32.x - instead of the expected internet IP.

Suggestions to tshoot are appreciated
0
Comment
Question by:isltt
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
  • +1
7 Comments
 
LVL 5

Expert Comment

by:tmehmet
ID: 13515855
Have you got a static outbound NAT to tell the firewall to make the internal 192* appear as the public IP?

0
 

Author Comment

by:isltt
ID: 13524126
yes there is
0
 
LVL 5

Expert Comment

by:tmehmet
ID: 13524279
Have you tried not using the Static outbound NAT?

If so, what was the result?
0
When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

 
LVL 12

Expert Comment

by:srikrishnak
ID: 13527730
Well...If you do a NAT you can check from the log files...Either static or Hide mode NAT it will works fine...Can you tell us the version of CP you are using..NG or ??
0
 

Author Comment

by:isltt
ID: 13528190
no I haven't tried not using the static outbound nat as  yet - strange thing is that I can access my internal server when i connect from the 'outside' using an ISP on the internet..which kinda indicates to me that natting works

It's CP NG...what specifically do you want me to check in the log?
0
 
LVL 12

Expert Comment

by:srikrishnak
ID: 13528276
???..You mean its working from outside..That means NAT is working..okie what i asked you is you can check from the Smartviewer how the packet is being translated...
0
 
LVL 3

Accepted Solution

by:
yokel earned 1500 total points
ID: 13533242
Is the remote trusted netwoks internal IP address 192.168.32.x?
If so, then it sounds like that they are not NATing their private address to their public IP address.

When you see the ping packet coming in, what is the source IP address, public or private? If private (192.168.32.x), then the trusted site have to sort out their NATing.

Cheers
0

Featured Post

Four New Appliances. Same Industry-leading Speeds.

But don't take it from us.  The Firebox M370 is Miercom tested and Miercom approved, outperforming its competitors for stateless and stateful traffic throughput scenarios.  Learn more about the M370, M470, M570 and M670 and find the right solution for your organization today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…
Suggested Courses
Course of the Month10 days, 10 hours left to enroll

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question