- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
There is a firewall 5400. On the firewall three interfaces:
1. LAN - 10.1.1.1
2. DMZ - 172.16.0.1
3. EXTERNAL- 85.1.1.100
It is necessary to publish the web server (on the local network) outside so that:
1. WEB server (LAN)<->DMZ - without NAT
2. External <-> WEB server (LAN) - via a specific ip address (85.1.1.105)
3. WEB server (LAN) <->External - via a specific ip address (85.1.1.105)
How to write a static NAT rule I understand, but how to make sure that traffic is not between Web server and DMZ?
Hi Andrey,
There should be subnets defined in LAN as well as in DMZ. so you can make groups of LAN subnet and DMZ subnet. After that you can put Manual NAT rule from LAN to DMZ and vice versa with No NAT. For remaining traffic you can use static NAT.
Hope I answered your question.
Hi Andrey,
There should be subnets defined in LAN as well as in DMZ. so you can make groups of LAN subnet and DMZ subnet. After that you can put Manual NAT rule from LAN to DMZ and vice versa with No NAT. For remaining traffic you can use static NAT.
Hope I answered your question.
How to make a rule without NAT, can show or example lead? Thank you.
Hi,
You can keep packet as "original" in translated packet field.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY