Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Hugo_vd_Kooij
MVP Gold
MVP Gold
Jump to solution

Managing firewalls behind externaly managed NAT?

We have a business case where we need to managed gateways (3 clusters) through a NATted connection where the NATting is done by an externally managed firewall.

So we have a cluster with an external interface 10.12.34.(1,2,3) and an internal interface 10.56.78.(1,2,3) but we can't reach these firewalls directly. We have to use a VPN and we have to use NAT as we can't manage 10.x.x.x.x on our management setup (it's a CMA on a MDS).

In my view the only thing I need to do is to change the Main IP address to our NAT range for this customer 100.72.12.(1,2,3) on the management side.

This should not change anything in regards to how the firewall operates as we only use the Firewall and IPS blades.

Or am I missing something?

<< We make miracles happen while you wait. The impossible jobs take just a wee bit longer. >>
0 Kudos
1 Solution

Accepted Solutions
Don_Paterson
MVP Gold
MVP Gold

If they're R82 boxes then there is the new Management Behind NAT feature for that. 

https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Cont...

 

View solution in original post

2 Replies
Don_Paterson
MVP Gold
MVP Gold

If they're R82 boxes then there is the new Management Behind NAT feature for that. 

https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Cont...

 

the_rock
MVP Diamond
MVP Diamond

Hey Hugo,

What Don had sent looks correct.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events