Re: Routing for a Virtual Server in Checkpoint
- From: "Will" <DELETE_westes@xxxxxxxxxxxxxxxxxx>
- Date: Sun, 17 Sep 2006 23:58:53 -0700
Will <westes-usc@xxxxxxxxxxxxxx> wrote:interface.
: With at least older versions of Checkpoint, you have to establish manual
: routes in the OS to move packets that require NAT to the correct
: For a simple mapping of one external IP to one internal IP, this istrivial
: and works fine. But how are you supposed to do the routing for thecase of
: a virtual server, where one external IP may map each of three ports tothree
: separate destination IPs on three separate DMZ networks? It's notclear
: for such a case how static routing rules would apply.
<larstr@xxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:eeis30$83b$1@xxxxxxxxxxxxxxxxxxxxx
I don't know what version you're using, but newer versions (NG and up)
understands and does this automaticly. It's called automatic ARP.
Don't confuse the arp issue with NAT. At least on the older Checkpoint
product, they are completely separate. You have to define static routes on
the pre-NAT addresses in order to have them routed to the correct
destination interface.
If you automate the arp, and you want to use NAT after routing, wouldn't you
still need to create static routes to get to the correct destination
interface?
My case is a little too complex for a simple static route. I want:
192.168.10.13:80 -> 172.16.16.14:8080
192.168.10.13:53-> 172.16.13.13:53
172.16.16 and 172.16.13 are separate class C networks on separate DMZ
interfaces of the firewall. I can't just route all packets coming to
19.168.10.13 to one of these two destinations arbitrarily.
--
Will
.
- References:
- Routing for a Virtual Server in Checkpoint
- From: Will
- Re: Routing for a Virtual Server in Checkpoint
- From: larstr
- Routing for a Virtual Server in Checkpoint
- Prev by Date: Re: Trouble with network using netgear router
- Next by Date: Re: Routing for a Virtual Server in Checkpoint
- Previous by thread: Re: Routing for a Virtual Server in Checkpoint
- Next by thread: Re: No internet connection
- Index(es):
Relevant Pages
|