Re: Routing for a Virtual Server in Checkpoint
- From: "Will" <DELETE_westes@xxxxxxxxxxxxxxxxxx>
- Date: Mon, 18 Sep 2006 00:02:25 -0700
"Jean-François Gobin" <jf-no-spam-for-me@xxxxxxxxxx> wrote in message
news:450d1610$0$428$4d4efb8e@xxxxxxxxxxxxxxxxxxxxxx
In fact it depends if you're doing prenat or postnat. One of them doesn't
require routes at all, but beware ... you may need to review your entire
rulebase (prenat is doing the NAT or de-NAT on the input interface
...postnat on the output interface). That's what they call "client side
natting" or "server side natting".
What's the general opinion on which form of NAT is more secure?
The routes you have to insert in the OS are only to determine "to whichno
interface should this packet be sent". Quite logical if you think that the
address in question may be connected to the outside interface or even to
interface (case of a "pure virtual network").
Right, but my question (still unanswered) is how do I do those routes when I
have one external IP, with three target ports that I want to map to three
different target computers on three different DMZ networks? I can't just
route one static IP to one static IP, and I can't route the one IP to one
DMZ network. That will deliver the packet to the incorrect DMZ interface
for two of the three target hosts.
"Automatic ARP" is there only to ensure that the NAT address can beresolved
to a physical (ie ethernet) address. Without that, you'll have to inserthide)
proxy ("permanent public" in term of BSD) arp for each nat (static or
you can have ... or insert host routes in your outside router.
I'm not having any problems with the arp part of this.
--
Will
.
- Follow-Ups:
- Re: Routing for a Virtual Server in Checkpoint
- From: Jean-François Gobin
- Re: Routing for a Virtual Server in Checkpoint
- References:
- Routing for a Virtual Server in Checkpoint
- From: Will
- Re: Routing for a Virtual Server in Checkpoint
- From: larstr
- Re: Routing for a Virtual Server in Checkpoint
- From: Greg Hennessy
- Re: Routing for a Virtual Server in Checkpoint
- From: Jean-François Gobin
- Routing for a Virtual Server in Checkpoint
- Prev by Date: Re: Routing for a Virtual Server in Checkpoint
- Next by Date: New "worst nightmare" for network admins
- Previous by thread: Re: Routing for a Virtual Server in Checkpoint
- Next by thread: Re: Routing for a Virtual Server in Checkpoint
- Index(es):
Relevant Pages
|