Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Firewall_Head
Explorer
Jump to solution

Unable to create destination NAT rule for ICMP service

Dear Checkmates,

I'm having problem creating DST NAT rule for an ICMP traffic, I'm forced to create a rule with services as "ANY" for this to work. 

Can someone let me know if this is a limitation and so please share the relevant document from Check Point.

Thanks in advance!

=======

WR,

FH

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

The NAT rulebase only permits usage of TCP and UDP services. 
I don't believe this is explicitly documented as SmartConsole provides an appropriate error when you attempt this configuration.
This is also a long-standing limitation going back to the earliest days of the product.

Having said that, the NAT rulebase only applies if the traffic is permitted by the Access Policy.

View solution in original post

4 Replies
Lesley
Mentor Mentor
Mentor

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...

NAT (Network Address Translation) is a feature of the Firewall Software Blade

Lesley_0-1736930943173.gif

 

 and replaces IPv4 and IPv6 addresses to add more security. NAT protects the identity of a network and does not show internal IP addresses to the Internet.

The Security Gateway can change:

  • The source IP address in a packet.

  • The destination IP address in a packet.

  • The TCP / UDP port in a packet. (ICMP is not TCP or UDP)

-------
If you like this post please give a thumbs up(kudo)! 🙂
PhoneBoy
Admin
Admin

The NAT rulebase only permits usage of TCP and UDP services. 
I don't believe this is explicitly documented as SmartConsole provides an appropriate error when you attempt this configuration.
This is also a long-standing limitation going back to the earliest days of the product.

Having said that, the NAT rulebase only applies if the traffic is permitted by the Access Policy.

Lesley
Mentor Mentor
Mentor

You get a validation error when you try to sneak ICMP in a group in the rule. If you try to select icmp itself you cannot find it to select in the drop down menu 

-------
If you like this post please give a thumbs up(kudo)! 🙂

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events