RE: [Full-Disclosure] PIX vs CheckPoint

From: Perrymon, Josh L. (PerrymonJ_at_bek.com)
Date: 06/30/04

  • Next message: Perrymon, Josh L.: "RE: [Full-Disclosure] Tools for checking for presence of Adware r remotely"
    To: "'Cyril Guibourg'" <plonk-o-matic@teaser.fr>, "Otero, Hernan (EDS)" <HOtero@lanchile.cl>
    Date: Wed, 30 Jun 2004 15:28:03 -0500
    
    

    That is odd. You *must have some translations in place. Because you *must
    have (2) different subnets. ( One outside and another on the inside ) So
    when a packets transverses the pix and is sent outbound it must be
    translated - Nat inside / Outside
    or Nat 0 when using VPNs.

    JP

    -----Original Message-----
    From: Cyril Guibourg [mailto:plonk-o-matic@teaser.fr]
    Sent: Wednesday, June 30, 2004 1:18 PM
    To: Otero, Hernan (EDS)
    Cc: full-disclosure@lists.netsys.com
    Subject: Re: [Full-Disclosure] PIX vs CheckPoint

    "Otero, Hernan (EDS)" <HOtero@lanchile.cl> writes:

    > I think you do, because at least a nat 0 itīs needed to get traffic
    passing
    > through the pix.

    This is odd, I do have a running config under 6.2 without any nat statement.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Perrymon, Josh L.: "RE: [Full-Disclosure] Tools for checking for presence of Adware r remotely"

    Relevant Pages

    • Re: Static Translations Disappearing
      ... this router and see if they have the same behavior. ... you are running into a NAT bug. ... It wouldn't hurt to change IOS and ... ....where it just shows all translations being dynamic (0 static, ...
      (comp.dcom.sys.cisco)
    • Re: Static Translations Disappearing
      ... I bought a Cisco 837 ADSL router a couple of months ago, ... I'm having though is that static translations I've configured in the ... I've been logging NAT translations out to syslog and this has ... encapsulation aal5mux ppp dialer ...
      (comp.dcom.sys.cisco)
    • Re: Static Translations Disappearing
      ... I'm having though is that static translations I've configured in the ... I've been logging NAT translations out to syslog and this has ... encapsulation aal5mux ppp dialer ... I looked at the source ports the system was using for outbound TCP ...
      (comp.dcom.sys.cisco)
    • Re: 2610 Nat or problem with browsing web
      ... Let me start by saying I'm online and NAT is ... MISSES and EXPIRED TRANSLATIONS increase. ... service timestamps debug datetime msec ... Create a ~256KB in memory logging buffer ...
      (comp.dcom.sys.cisco)
    • Re: CPU utilization on the router.
      ... fast switching operation (using cpu interrupts), but I think latest IOS-es are using CEF for NAT since you have 'CEF translated packets" counter in the 'show ip nat stat' command output. ... p2p clients are causing a lot of NAT translations by single host since they are connected with multiple peers - thus there are multiple NAT translations generated by a single host. ...
      (comp.dcom.sys.cisco)