RE: [fw-wiz] Checkpoint NAT H.323 support

From: Warren Verbanec (Warren.Verbanec_at_resilience.com)
Date: 11/23/04

  • Next message: JERRY MURTLAND: "Re: [fw-wiz] Odd scan to port 36867"
    To: "Rob Hughes" <rob@robhughes.com>, <firewall-wizards@honor.icsalabs.com>, <fw1-gurus@lists.phoneboy.com>
    Date: Tue, 23 Nov 2004 13:29:54 -0800
    
    

    Hi

    As of R55 HFA 08 or so, FW-1 has supported H.323 v2 and v4 quite nicely. NATted gatekeepers should be translated just fine in the H.225 stream.

    Please check your configuration over. What kind of H.323 gear is this?

    -Warren Verbanec
    Resilience Corporation

    -----Original Message-----
    From: Rob Hughes [mailto:rob@robhughes.com]
    Sent: Saturday, November 20, 2004 3:39 PM
    To: firewall-wizards@honor.icsalabs.com
    Subject: Re: [fw-wiz] Checkpoint NAT H.323 support

    On Thu, 2004-11-18 at 16:46 +0100, Luis Maria Sainz Caballero wrote:
    > Hi people,
    >
    > I am new to the list and I hope you help me. I have a problem with
    > FW-1/VPN-1 NG with AI (R55) and the H.323 support. I am trying to register
    > (H.323 RAS) a VoIP gateway inside my trusted network with a gatekeer on
    > the Internet. I have already configured the VoIP domains (one for the
    > gateway and another for the gatekeeper) in the FW, applied the last hotfix
    > acumulator (HFA_11) and configured static NAT for the internal gateway to
    > a public IP.
    > The gatekeeper cannot respond because the IP inside the h225 payload isn't
    > traslated, and I have confirmed it using the monitor inside de Firewall
    > (fw monitor).
    > Anybody know if Checkpoint really suports H.323 NAT? or can be a problem
    > of mixconfiguration?
    >

    What does your rule look like? Specifically, what service are you using?
    Also, the CP docs have examples of how to set this up. Have you tried
    following those? But yes, it does (mostly) work.
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: JERRY MURTLAND: "Re: [fw-wiz] Odd scan to port 36867"

    Relevant Pages

    • Re: Cannot setup ICS in Win2000
      ... > * I have followed every Guide that I can find to try and make a> internet connection from one computer to another. ... > - Intel PIII-550mhz ... > * The Ipconfig in CMD Shows for the Intel PIII-550> Windows 2000 IP Configuration ... Primarily the> Gateway is failed, But I have found no discriptions on how to use the> gateway. ...
      (microsoft.public.win2000.networking)
    • [fw1-gurus] RE: [fw-wiz] Checkpoint NAT H.323 support
      ... Please check your configuration over. ... > gateway and another for the gatekeeper) in the FW, ... and I have confirmed it using the monitor inside de Firewall ...
      (Firewall-Wizards)
    • Workgroup that spans more than one subnet in Samba
      ... I want a workgroup that spands two IP subnets. ... eth0:192.168.0.1 and gateway of the 192.168.0.0/24 ... The Gateway is a Fedora Core 3 box where I have Samba ... running with this configuration: ...
      (comp.os.linux.networking)
    • RE: ISA 2004 Firewall Client and ActiveSync 4.2
      ... though I was connected in a Wireless Lan I changed my configuration. ... that killing my default gateway is not the way ... gateway and the appropriate DNS server entries. ... server internal IP then your client works as a secureNAT client and you're ...
      (microsoft.public.isa.clients)
    • Re: [SLE] Wireless, DHCP, Firewall Issues [SOLVED, sort of ...]
      ... I setup my laptop with SCP. ... It "remembers" changes to your configuration and switches back and forth ... wireless with DHCP accept any... ... I also blanked the gateway information. ...
      (SuSE)