Solved

Publish Email Server through Checkpoint 2210 Firewall

Posted on 2013-06-07
1
967 Views
Last Modified: 2013-06-11
We have a new Checkpoint 2210 firewall running Gaia R76 and I'm playing around learning how to use it (we had ISA Server 2004 before this).  My first challenge is publishing SMTP access to our mail server (Exchange 2003 running on Server 2003 Std).  This is our network:
   
    Internet -> Router (192.168.40.1) -> (192.168.40.2) Firewall (172.16.1.254) -> Mail Server (172.16.1.23)

We only have a single "real" Internet IP address for the whole company.

I setup a host node for the mail server (Savanah) and the firewall's external IP address (ADSL).  I then created an address range to cover our 172.16.0.0 network (Internal).  Then, I created 2 NAT rules:

    Source      Dest    Srv      Source     Dest        Srv
    Savanah   Any      Any     ADSL       Original   Original
    Any           ADSL   smtp   Original   Savanah  Original

I also created the policy rule:

    Source            Dest    Srv       Action   Track
    Not Internal   ADSL   smtp   accept   log

Finally, I installed the policy.  I can see in SmartView Tracker that packets are being accepted and that the XlateDest column shows that the destination IP address is being changed to Savanah.  But, attempts to connect are just timing out.  What am I missing?
0
Comment
Question by:CIPortAuthority
1 Comment
 

Accepted Solution

by:
CIPortAuthority earned 0 total points
ID: 39237572
It turns out that the packets were getting through to the mail server but it had the wrong default gateway so nothing was getting back to the firewall. I was getting confused because I could ping the mail server from the firewall (and even Telnet to port 25) but couldn't get through from the Internet.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
SonicWall Pro 300 Firmware 2 112
How to export list of ssl vpn users in a dell sonicwall 4 106
Fortigate 100D NTP Issue 4 111
What are acceptable WiFi signal strengths 6 72
In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question