Checkpoint NG FP3 and Multiple Interfaces

From:
Date: 10/30/02


Date: Wed, 30 Oct 2002 05:52:58 GMT

All,

I've got two Checkpint NG FP3 firewalls set up in a cluster XL
configuration. They have multiple interfaces. One interface is connected
to my Intranet, one for sync, one for UFP/CVP servers, one for a protected
DMZ, and one that connects to the Internet. I want to bring in my external
hosts and set them up on my protected DMZ. This network utilizes private
address ranges as specified in RFC 1918. The firewall configuration is
setup to statically NAT the DMZ hosts to the Internet, and to hide via NAT
the Intranet clients. I find that when I connect to the protected DMZ
hosts, the firewall is NATing their connection. I also find that when I
connect from the Protected DMZ hosts to some resources on the Intranet that
the firewall is again NATing the protected DMZ hosts to the Intranet. My
question is this...is there any way to only NAT Intranet and Protected DMZ
hosts to the Internet, and not have the firewall apply NAT rules to
communication that takes place between those two interfaces? Possibly by
manually manipulation the configuration and overriding the auto-generated
NAT rules? Any input is greatly appreciated. Thanks.

Mike



Relevant Pages

  • Re: How to get through iptables/NAT, reality and risk calculation
    ... IRC and the like allowed in your intranet is quite a risk. ... Your firewall could be easily fooled if the connection starts from the ... Basically you can not rely on the assumption that a connection initiated ...
    (Security-Basics)
  • Re: Internet Explorer displays "Error on page"
    ... Yes we do have firewall in the company. ... IE6.0 in 2000 pro PCs. ... pages in the Intranet. ... click on the error icon to display the ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: [fw-wiz] Protecting a datacentre with a firewall
    ... bad at recognizing that their intranet is not much better defended ... and compartment them with a firewall. ... audit services, and information flow control. ... In a larger enterprise it tends to be something near untreatable. ...
    (Firewall-Wizards)
  • Re: Setting up Intranet
    ... I thought that an Intranet being inside and not on an Internet Web Server ... The Lan is behind a firewall, ...
    (microsoft.public.windowsxp.network_web)