Issue with NAT on Checkpoint NG firewall unable to connect externally

I'm having a strange problem with my firewall, a Checkpoint NG with Application Intelligence (R55). I have a range of four IP addresses allocated by my ISP. The first one is used for the gateway, the second is for our mail server which also runs Outlook Web Access, the third is for a DMZ and the 4th is spare. I have NAT configured to translate from the mail server (192.168.40.2) to the second IP in our range, I'll call it x.x.x.2. I did this by right clicking on the node and going to edit, then on the NAT tab I selected "Add Automatic Address Translation rules", set the method to "Static" and entered the IP, x.x.x.2. I also have a NAT entry for our internal network, 192.168.40.0, to the first IP in our range, x.x.x.1.

The problem is, for some reason the mail server can no longer access the external network. It is configured to use the fileserver as a DNS server, so for example when I ping www.google.com, it resolves the IP address but the packets fail to get through the firewall. If I disable the NAT for the mailserver, it can ping the outside world without problems. At the moment, I've disabled all of the security policies so that all traffic on all ports can get through, just to make sure it wasn't a problem with a rule. I'm completely stumped as to why this doesn't work... any insight guys? At the moment we're unable to send or receive any email externally, as we use MessageLabs to filter our email, and they are only forwarding mail to the x.x.x.2 address. I need to get this fixed asap! Thanks!
LVL 3
Jm_saundersAsked:
Who is Participating?
 
Computer101Connect With a Mentor Commented:
PAQed with points refunded (500)

Computer101
EE Admin
0
 
LBACISCommented:
If it is on a Nokia appliance check your voyager and make sure there is nothing NAT there.
0
 
Jm_saundersAuthor Commented:
It's on the SecurePlatform (SPLAT), and I've resolved the issue now.

Cheers,

James
0
Will You Be GDPR Compliant by 5/28/2018?

GDPR? That's a regulation for the European Union. But, if you collect data from customers or employees within the EU, then you need to know about GDPR and make sure your organization is compliant by May 2018. Check out our preparation checklist to make sure you're on track today!

 
Keith AlabasterEnterprise ArchitectCommented:
James, post the resolution and I can refund your points

regards

Keith
0
 
Jm_saundersAuthor Commented:
Somebody had added a switch between the firewall and the internet, and connected a router into it... and gave the router the same IP address as my mailserver. This meant that the packets could leave the firewall from the mailserver, but they'd get returned to this router that was sitting outside my firewall. I didn't know about this until, in an act of desperation, I went and unplugged everything and connected it all up again. I just unplugged the switch and the extra router, and everything started working again properly.

Cheers,

James
0
 
Keith AlabasterEnterprise ArchitectCommented:
Thanks :)

I'll make the recommendation for PAQ and points refunded on my next sweep through which will be a couple of days.

Thanks
Keith
0
All Courses

From novice to tech pro — start learning today.