• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1045
  • Last Modified:

How to Prevent Checkpoint NAT from Changing Port Mapping

We are looking for a way to configure a Checkpoint R65 based NAT to not periodically change source port mapping for NATted UDP communication.  From network sniffs on the WAN side of the NAT we see that the source port (from the NAT) is incremented by one every few minutes.  Is there a way to disable this behavior such that the source port remains fixed, or to increase the interval at which this occurs.  BTW a static NAT is not an option for security reasons.  Many thanks.
0
dmb17
Asked:
dmb17
1 Solution
 
deimarkCommented:
In short, yes you can.

Instead of using automatic NAT rules, ie hide the internal networks behind the external interface, which will use port translation too, you can also create your own manula nat rules where the source port is untranslated.

Be aware though, the automatic nat and port translation do help in most instances and you need be sure that you are not going to break anything by using the manual rules with no port translation.
0

Featured Post

Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now