Problem with FTP and NAT
From: Tony Hewitson (hewitsan@email.lul.co.uk)Date: 06/18/02
- Next message: Harry Krause: "Re: The Beginning Of The End For Micro$oft Reign Of Terror"
- Previous message: David J Edgar: "Alcatel Speedtouch 510 - H323/H245 setup"
- Next in thread: Brad Werschler: "Re: Problem with FTP and NAT"
- Reply: Brad Werschler: "Re: Problem with FTP and NAT"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: hewitsan@email.lul.co.uk (Tony Hewitson) Date: 18 Jun 2002 02:38:42 -0700
I recently had a problem with checkpoint FW4.1 SP4 on a nokia ip650 -
The Nokia has three subnets attached to it, the first is the internet,
the second a dmz and the third the private network. We setup two
network objects in checkpoint one was for the internal network
(10.0.0.0/8) and the other was for the dmz (10.100.2.72/26) in the dmz
we have a proxy server to which all HTTP and FTP requests to the
internet are sent. The DMZ is using 'hide ' nat behind one of our
legal internet ip addresses. The problems is we are having verrrry
slow HTTP access and intermittent FTP connections with this setup. I
reproduced this problem in a laboratory environment - the firewall had
no rules applied to it (any any any accept) and we still had a problem
when using NAT to the internet from the DMZ. I then changed the
network of the DMZ to 192.168.1.0 and wham everything worked as it
should. Is this because Checkpoint is aware of the two network objects
(even when they are not loaded into the policy and the dmz natted) and
the DMZ is in essence encorporated into the internal network object by
using 10.0.0.0/8??
any ideas would be greatly appreciated
Regards
Tony Hewitson
- Next message: Harry Krause: "Re: The Beginning Of The End For Micro$oft Reign Of Terror"
- Previous message: David J Edgar: "Alcatel Speedtouch 510 - H323/H245 setup"
- Next in thread: Brad Werschler: "Re: Problem with FTP and NAT"
- Reply: Brad Werschler: "Re: Problem with FTP and NAT"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|