Solved

How to Prevent Checkpoint NAT from Changing Port Mapping

Posted on 2009-06-29
2
912 Views
Last Modified: 2013-11-16
We are looking for a way to configure a Checkpoint R65 based NAT to not periodically change source port mapping for NATted UDP communication.  From network sniffs on the WAN side of the NAT we see that the source port (from the NAT) is incremented by one every few minutes.  Is there a way to disable this behavior such that the source port remains fixed, or to increase the interval at which this occurs.  BTW a static NAT is not an option for security reasons.  Many thanks.
0
Comment
Question by:dmb17
2 Comments
 
LVL 18

Accepted Solution

by:
deimark earned 500 total points
ID: 24742953
In short, yes you can.

Instead of using automatic NAT rules, ie hide the internal networks behind the external interface, which will use port translation too, you can also create your own manula nat rules where the source port is untranslated.

Be aware though, the automatic nat and port translation do help in most instances and you need be sure that you are not going to break anything by using the manual rules with no port translation.
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Suggested Solutions

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Hi All,  Recently I have installed and configured a Sonicwall NS220 in the network as a firewall and Internet access gateway. All was working fine until users started reporting that they cannot use the Cisco VPN client to connect to the customer'…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now