Re: NG - NAT & UDP

From: Pete (Pete@Pete.com)
Date: 11/29/02

  • Next message: Dazz: "Re: A Royal Name"
    From: "Pete" <Pete@Pete.com>
    Date: Fri, 29 Nov 2002 17:52:28 +1300
    
    

    Hi AD

    Have you got a static route to the NAT address on the firewall?

    Pete

    "AD" <ajd777@hotmail.com> wrote in message
    news:3de5c0e9$0$4785$fa0fcedb@lovejoy.zen.co.uk...
    > Hi All,
    >
    > I have a small problem with Static NAT and incoming udp.
    >
    > I have setup Checkpoint NG FP2 on a windows 2000 (for my sins) I have
    setup
    > rules to allow incoming udp on port 6257 (for winmx). I have static hide
    NAT
    > rule for all outgoing traffic and detination NAT rule for incoming winmx
    > traffic. (all created manually, ie not automatic nat rules)
    >
    > I can see the traffic being accepted by the fw but the incoming udp
    packets
    > never seem to reach the internal pc.
    >
    > Everything else works fine.
    >
    > What am i doing wrong!
    >
    > One other thing. In the log viewer i dont see xlatesrc and xlatedst fields
    > populated, as i thought i would?
    >
    > thanks
    >
    > AD
    >
    >



    Relevant Pages

    • Re: Azureus and the TCP port 6881
      ... NAT howto and I was scared... ... following message: "Testing port 6881... ... More than likely you'll need to setup a NAT rule in iptables. ...
      (Debian-User)
    • Re: NG - NAT & UDP
      ... I tried adding a static route but all NAT stopped working when i did that! ... >> I have a small problem with Static NAT and incoming udp. ... >> rule for all outgoing traffic and detination NAT rule for incoming winmx ...
      (comp.security.firewalls)
    • Re: Applying NAT Rules in Firewall-1 To External Targets Only?
      ... internal DMZ host sends packets to the external interface then NAT is ... From <internal host> To All use external NAT IP for internal host ... Put the internal/dmz nets into groups to ... allow them to be aggregated into a single nat rule. ...
      (comp.security.firewalls)
    • Re: PF NAT regression
      ... I found out the following in /etc/pf.conf does not work anymore: ... You could also try to limit the nat rule by specifying "inet". ... I do not understand how could it have happened - it seemed clear to me before - first version -> no NAT vs. second version -> NAT. ... There is only one IP address on the sis0 interface and it is being assigned by DHCP. ...
      (freebsd-current)
    • Re: selective NAT/gateway
      ... then in the nat rule: ... routes a small subnet of static IP's to our servers, ... between internal subnets. ... NAT translation over the PPPoE link. ...
      (freebsd-questions)

  • Quantcast