CheckPoint hide nat, static nat

Feb 04, 2005 2 Replies

A proxy arp on the firewall for the 192.168.20.2 address followed by a nat translaion for anything Source: 192.168.20.0/24 Destination: 192.168.20.2 NAT Source: Address on the 192.168.10.0/24 network Destination: original

Hello,



Here is my topology, quickly.



Nokia IP380, 4 network adapters in use.



eth1c0 : 192.168.10.1 (/24) eth2c0 : 192.168.20.1 (/24) eth3c0 : 192.168.30.1 (/24) eth4c0 : 195.238.10.10 (/28)



on eth1c0's network, I have a host 192.168.10.10



My question:



When 192.168.10.10 wants to talk to 192.168.20.0/24, he has to be nated to 192.168.20.2



On the NAT tab, I have something like this for the inbound



.. Before NAT Source: 192.168.10.10 Destination: 192.168.20.0/24 || .. NAT Source 192.168.20.2 Destination: original



What do I need to make the outbound realistic?


192.168.20.2 does not exist really, this is kind of a virtual ip just existing on the firewall itself...

What would you add for the retourn rule? I can't address 192.168.20.2...



Thanks,



RC


Do not NAT the internal networks communicating with each other at all. NAT only traffic to the internet (hide behind eth4c0). That will save you from a lot of headache.

No, why do you want to NAT it?

Wolfgang

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required