[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

Issue with NAT on Checkpoint NG firewall unable to connect externally

Posted on 2006-11-06
7
Medium Priority
?
740 Views
Last Modified: 2013-11-16
I'm having a strange problem with my firewall, a Checkpoint NG with Application Intelligence (R55). I have a range of four IP addresses allocated by my ISP. The first one is used for the gateway, the second is for our mail server which also runs Outlook Web Access, the third is for a DMZ and the 4th is spare. I have NAT configured to translate from the mail server (192.168.40.2) to the second IP in our range, I'll call it x.x.x.2. I did this by right clicking on the node and going to edit, then on the NAT tab I selected "Add Automatic Address Translation rules", set the method to "Static" and entered the IP, x.x.x.2. I also have a NAT entry for our internal network, 192.168.40.0, to the first IP in our range, x.x.x.1.

The problem is, for some reason the mail server can no longer access the external network. It is configured to use the fileserver as a DNS server, so for example when I ping www.google.com, it resolves the IP address but the packets fail to get through the firewall. If I disable the NAT for the mailserver, it can ping the outside world without problems. At the moment, I've disabled all of the security policies so that all traffic on all ports can get through, just to make sure it wasn't a problem with a rule. I'm completely stumped as to why this doesn't work... any insight guys? At the moment we're unable to send or receive any email externally, as we use MessageLabs to filter our email, and they are only forwarding mail to the x.x.x.2 address. I need to get this fixed asap! Thanks!
0
Comment
Question by:Jm_saunders
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 4

Expert Comment

by:LBACIS
ID: 17888657
If it is on a Nokia appliance check your voyager and make sure there is nothing NAT there.
0
 
LVL 3

Author Comment

by:Jm_saunders
ID: 17889001
It's on the SecurePlatform (SPLAT), and I've resolved the issue now.

Cheers,

James
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 18059441
James, post the resolution and I can refund your points

regards

Keith
0
Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

 
LVL 3

Author Comment

by:Jm_saunders
ID: 18061049
Somebody had added a switch between the firewall and the internet, and connected a router into it... and gave the router the same IP address as my mailserver. This meant that the packets could leave the firewall from the mailserver, but they'd get returned to this router that was sitting outside my firewall. I didn't know about this until, in an act of desperation, I went and unplugged everything and connected it all up again. I just unplugged the switch and the extra router, and everything started working again properly.

Cheers,

James
0
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 18062359
Thanks :)

I'll make the recommendation for PAQ and points refunded on my next sweep through which will be a couple of days.

Thanks
Keith
0
 
LVL 1

Accepted Solution

by:
Computer101 earned 0 total points
ID: 18136455
PAQed with points refunded (500)

Computer101
EE Admin
0

Featured Post

Q2 2017 - Latest Malware & Internet Attacks

WatchGuard’s Threat Lab is a group of dedicated threat researchers committed to helping you stay ahead of the bad guys by providing in-depth analysis of the top security threats to your network.  Check out our latest Quarterly Internet Security Report!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
Video by: ITPro.TV
In this episode Don builds upon the troubleshooting techniques by demonstrating how to properly monitor a vSphere deployment to detect problems before they occur. He begins the show using tools found within the vSphere suite as ends the show demonst…
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question