nat @ wins issue w/FW4.1

From: Bob Perez (bperez77@hotmail.com)
Date: 06/28/02


From: bperez77@hotmail.com (Bob Perez)
Date: 28 Jun 2002 12:32:56 -0700

I have an issue with Wins responses and natting.

In my firewall I have a rule that says if you are headed to a
particular external ISP address, once it hits the FW NAT itto an
Internal server address. This works fine no problems.

But when I dial in and I try to ping by host name to that internal
machine it resolves to the external address. I see the packet coming
across the FW to the WINS server and I see the response from the WINS
server to the machine and then the ping begins but what is odd is that
the FW NATTED the response address to the external address. I also
have a rule before my nat rule that says "If internal net dest for any
int net keep all originals which should cause the external nat rule to
never be reached.

I also know the firewall is doing the nat on the wins request cause if
I disable the rule it all works fine. Also, if I ping the netbios
name with the DNS suffix applied to it, it works fine as well too.
The problem only occurs when pinging the netbios name and the dial up
connection has no DNS suffix attached to it. So the workaround is to
attach a DNS suffix but I would like to resolve the issue in the FW.
Thanks.

Checkpoint 4.1 Nokia IP 330



Relevant Pages

  • nat @ wins issue w/FW4.1
    ... across the FW to the WINS server and I see the response from the WINS ... have a rule before my nat rule that says "If internal net dest for any ... I also know the firewall is doing the nat on the wins request cause if ... name with the DNS suffix applied to it, it works fine as well too. ...
    (comp.security.firewalls)
  • Re: After a while all outbound connections get stuck in SYN_SENT
    ... response indicating that nothing's listening nor a ACK SYN response ... indicating that something *is* listening. ... firewall problems, ...
    (comp.lang.java.programmer)
  • Re: Xbox MCX Issue -- Cant View Online Spotlight Videos
    ... I don't have any third-party firewall running. ... and the MCX ... >> Thanks for your response. ... >> worked fine before I disable simple file sharing. ...
    (microsoft.public.windows.mediacenter)
  • Systemn Mechanic 7 Professional sucks!
    ... I posted below in response to someone who said never to use registry ... According to the advertising on the cover Iolo's product has one many ... awards and is also a virus protector and firewall. ... that should not be a critical error, ...
    (microsoft.public.windowsxp.general)
  • Re: Cant Logon
    ... In my first response I listed the options that were available to you to ... while the firewall was down. ... If you use an ADSL or a cable modem to connect ... While I understand that you prefer positive words from respondents, ...
    (microsoft.public.windowsxp.general)