?
Solved

How to Prevent Checkpoint NAT from Changing Port Mapping

Posted on 2009-06-29
2
Medium Priority
?
976 Views
Last Modified: 2013-11-16
We are looking for a way to configure a Checkpoint R65 based NAT to not periodically change source port mapping for NATted UDP communication.  From network sniffs on the WAN side of the NAT we see that the source port (from the NAT) is incremented by one every few minutes.  Is there a way to disable this behavior such that the source port remains fixed, or to increase the interval at which this occurs.  BTW a static NAT is not an option for security reasons.  Many thanks.
0
Comment
Question by:dmb17
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 18

Accepted Solution

by:
deimark earned 2000 total points
ID: 24742953
In short, yes you can.

Instead of using automatic NAT rules, ie hide the internal networks behind the external interface, which will use port translation too, you can also create your own manula nat rules where the source port is untranslated.

Be aware though, the automatic nat and port translation do help in most instances and you need be sure that you are not going to break anything by using the manual rules with no port translation.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
How to fix incompatible JVM issue while installing Eclipse While installing Eclipse in windows, got one error like above and unable to proceed with the installation. This video describes how to successfully install Eclipse. How to solve incompa…
Suggested Courses

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question