Re: Symantec Firewall Problem : Confusing !!

From: Lars M. Hansen (badnews@hansenonline.net)
Date: 01/27/03


From: Lars M. Hansen <badnews@hansenonline.net>
Date: Mon, 27 Jan 2003 11:45:11 GMT

On 27 Jan 2003 01:26:25 -0800, ANEJJAR spoketh

>Hi,
>
>Found no error ( warning, note, ...) about NAT or transform in logs!
>
>It seems as the SEF drops any packet originated from the internal host.
>

Ok, outbound address translation.

You have a dynamic NAT pool consisting of the public IP address(es) of
the mailserver, and a Address Transform created for the internal host
(mail server) to use the NAT pool when communicating with external
hosts?

Are you seeing any "arp" errors on the firewall regarding the NAT'ed
public IP address?

Lars M. Hansen
http://www.hansenonline.net
(replace 'badnews' with 'news' in e-mail address)



Relevant Pages

  • Re: Symantec Firewall Problem : Confusing !!
    ... Found no error about NAT or transform in logs! ... It seems as the SEF drops any packet originated from the internal host. ... Would it be a NAT ... > Check your log files for address transform or NAT pool error messages. ...
    (comp.security.firewalls)
  • Re: ASA 5500: connection is still on after the ACL is modified
    ... I still be able to access the internal host thru ... that connection even the access list does not allow that operation any ... Thanks, Brian, but I think xlate is for NAT translation table. ...
    (comp.dcom.sys.cisco)
  • Re: Problem on 1720 with overload nat
    ... Your dynamic nat pool access-list should include DENY entries for the ... > translation uses 10.208.7.13 (which is correctly blocked by the ...
    (comp.dcom.sys.cisco)
  • Re: Sonicwall newbie question...
    ... this is the normal LAN address of the server I ... that is supposed to access your internal host ... One-to-One NAT ... DHCP Server ...
    (comp.security.firewalls)
  • Outgoing PPTP traffic on a Cisco 1750
    ... Today I found out that clients inside can't VPN out to an external ... Microsoft VPN PPTP server. ... something with the NAT pool with the clients. ...
    (comp.dcom.sys.cisco)

Quantcast