Solved

Publish Email Server through Checkpoint 2210 Firewall

Posted on 2013-06-07
1
979 Views
Last Modified: 2013-06-11
We have a new Checkpoint 2210 firewall running Gaia R76 and I'm playing around learning how to use it (we had ISA Server 2004 before this).  My first challenge is publishing SMTP access to our mail server (Exchange 2003 running on Server 2003 Std).  This is our network:
   
    Internet -> Router (192.168.40.1) -> (192.168.40.2) Firewall (172.16.1.254) -> Mail Server (172.16.1.23)

We only have a single "real" Internet IP address for the whole company.

I setup a host node for the mail server (Savanah) and the firewall's external IP address (ADSL).  I then created an address range to cover our 172.16.0.0 network (Internal).  Then, I created 2 NAT rules:

    Source      Dest    Srv      Source     Dest        Srv
    Savanah   Any      Any     ADSL       Original   Original
    Any           ADSL   smtp   Original   Savanah  Original

I also created the policy rule:

    Source            Dest    Srv       Action   Track
    Not Internal   ADSL   smtp   accept   log

Finally, I installed the policy.  I can see in SmartView Tracker that packets are being accepted and that the XlateDest column shows that the destination IP address is being changed to Savanah.  But, attempts to connect are just timing out.  What am I missing?
0
Comment
Question by:CIPortAuthority
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 

Accepted Solution

by:
CIPortAuthority earned 0 total points
ID: 39237572
It turns out that the packets were getting through to the mail server but it had the wrong default gateway so nothing was getting back to the firewall. I was getting confused because I could ping the mail server from the firewall (and even Telnet to port 25) but couldn't get through from the Internet.
0

Featured Post

Are You Headed to Black Hat USA 2017?

Getting ready for Black Hat next week? Kick things off with the WatchGuard Badge Challenge and test your puzzle and cipher skills. Do you have what it takes to earn our limited edition Firebox Badge? Get started today - https://crimsonthorn.net

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I recently had the displeasure of buying a new firewall at one of the buildings I play Sys Admin at. I had to get a better firewall than the cheap one that I had there since I was reconnecting the main office to the satellite office via point-to-poi…
Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…
Suggested Courses

632 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question