Link to home
Start Free TrialLog in
Avatar of tryfwdtx
tryfwdtx

asked on

Checkpoint Firewall PAT/NAT not working

We have a CheckPoint UTM 576 TS appliance running NGX R65 build 19.
We are having a problem getting PAT and manual NAT to work.
We basically need to use a single external (public) IP to support multiple services on multiple internal servers. i.e. FTP, WEB, Email. Three different internal servers - one public IP.

Following advice from other forums, we believe that we have enabled Proxy ARP (how can we check for sure?)
We have added ARP entries for the external address with the MAC of the external interface to the local.arp file.
We have created manual NAT rules as advised by other forums and CP support (quoted below)
----------------
" Basically you would have to create manual NAT rules.  In the Original packet side you would create a new rule at the top with an ANY as the source, the destination object in the destination column,  put what service you want to use, then in the translated packet side for the source, leave it original for the source and then put the host as the destination and leave the service as original.

Then you would have to create the reverse rule for that traffic.  Create a rule beneath that one with this info.  On the Original Packet side put the host in the source field, leave the destination filed as ANY and the same service as you had in the first rule, then on the translated packet side, put the destination in the source field, leave the destination as original and service original.

Now you would have to do the same thing for all the services you want to use for the same destination as separate rules.

Then you would have to create a rule in the regular rule base for the traffic to pass."
--------------------
Still nothing works.
Other services that are NATed  1-to-1 work fine.
We are working in a test environment during the week and test changes and new ideas live on the weekend, after hours.
Any help is appreciated.
Thanks,


ASKER CERTIFIED SOLUTION
Avatar of grimkin
grimkin
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of tryfwdtx
tryfwdtx

ASKER

Thanks grimkin,
It took us a while to get to test in a live environment.
In addition, we also had to make manual entries into the local.arp file using the vi editor.
It is finally up and working and as of today we have it in production.