cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question

NAT policy rules for internal interfaces?

We don't appear to be able to get a NAT rule to apply on traffic on an internal interface of a Gaia security gateway.

Background:

We have been using Squid proxies for over 20 years and have a variety of systems and deployment tools that have the proxy hard coded (cache.lair.co.za:3128). Whilst it is possible to enable a proxy service on security gateways and edit the default port (8080) to match our legacy environment, application control doesn’t work due to them being written only to match on direct connections (tcp:80 and tcp:443) and HTTP and HTTPS proxy connections on tcp:8080.

 

We subsequently have to leave the security gateway proxy port configured as 8080 and wanted to create a NAT rule to redirect inbound connections towards the security gateway on 3128 to 8080.

What we did:

  • Created a NAT rule:

  • Testing:

[davidh@zajnb01-kvm2c ~]# telnet cache.lair.co.za 8080
Trying 100.127.254.1...
Connected to cache.lair.co.za (100.127.254.1).
Escape character is '^]'.

[davidh@zajnb01-kvm2c ~]# telnet cache.lair.co.za 3128
Trying 100.127.254.1...
telnet: connect to address 100.127.254.1: Connection refused

Are there restrictions on NAT policies that I'm perhaps unaware of?

Tags (2)
0 Kudos
2 Replies
Vladimir
Pearl

Re: NAT policy rules for internal interfaces?

You are not traversing the firewall. You are trying to connect to it on a different port to begin with.

0 Kudos

Re: NAT policy rules for internal interfaces?

Hi Vladimir,

Thanks, I'll NAT the connection before it reaches the Check Point then...

0 Kudos