Solved

Publish Email Server through Checkpoint 2210 Firewall

Posted on 2013-06-07
1
963 Views
Last Modified: 2013-06-11
We have a new Checkpoint 2210 firewall running Gaia R76 and I'm playing around learning how to use it (we had ISA Server 2004 before this).  My first challenge is publishing SMTP access to our mail server (Exchange 2003 running on Server 2003 Std).  This is our network:
   
    Internet -> Router (192.168.40.1) -> (192.168.40.2) Firewall (172.16.1.254) -> Mail Server (172.16.1.23)

We only have a single "real" Internet IP address for the whole company.

I setup a host node for the mail server (Savanah) and the firewall's external IP address (ADSL).  I then created an address range to cover our 172.16.0.0 network (Internal).  Then, I created 2 NAT rules:

    Source      Dest    Srv      Source     Dest        Srv
    Savanah   Any      Any     ADSL       Original   Original
    Any           ADSL   smtp   Original   Savanah  Original

I also created the policy rule:

    Source            Dest    Srv       Action   Track
    Not Internal   ADSL   smtp   accept   log

Finally, I installed the policy.  I can see in SmartView Tracker that packets are being accepted and that the XlateDest column shows that the destination IP address is being changed to Savanah.  But, attempts to connect are just timing out.  What am I missing?
0
Comment
Question by:CIPortAuthority
1 Comment
 

Accepted Solution

by:
CIPortAuthority earned 0 total points
ID: 39237572
It turns out that the packets were getting through to the mail server but it had the wrong default gateway so nothing was getting back to the firewall. I was getting confused because I could ping the mail server from the firewall (and even Telnet to port 25) but couldn't get through from the Internet.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…

864 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now