- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- How to nat a public ip address to local ip address...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to nat a public ip address to local ip address when acesss to my office via remote access vpn.
Hello Expert,
I am trying to obtain a private ip address as my source address when I establish a remote access vpn from home to my office.
example my isp provides a public during remote session, how could can I nat this ip address to a local ip address on my network.
The reason for this request is some applications requires a local ip address to allow connections.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unless the gateway doesn't have a Mobile Access or Remote Access license, you should be able to leverage Office Mode.
Specifically, when Remote Access clients connect, they are assigned an IP address an virtual interface on the client.
This IP (presumably on the local network) is used to originate all connections over the VPN.
NAT is not required.
However, Office Mode requires specific configuration.
If you can tell me what gateway/software version, I can provide a pointer to the relevant documentation for this.
If you don't have the appropriate license on the gateway OR the client was installed as SecuRemote, then you will see the behavior you're describing.
If you configure Office Mode and have the relevant license AND the client is installed as at least Check Point Mobile, you won't need NAT.
If you don't have the appropriate license, then you can configure IP Pool NAT.
See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello
Thanks for the prompt response
If you can tell me what gateway/software version, I can provide a pointer to the relevant documentation for this.
The software version is gaia R77.30 also the client is using client was installed as SecuRemote.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SecuRemote is the client version without license and without OfficeMode, see Remote Access Clients E84.30 Release Notes. Only if the public IP used for the client is always the same you could configure it using NAT in rulebase.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Albrecht,
The public IP used for the client for the client is always changing hence will be impossible to configure Nat in rulebase.
I notice you mention SeccRemote is client version without license and office mode is there an client version that can be
use that supports office mode?
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fact is that all other client flavours do support office mode 8) Find all of them in sk67820: Check Point Remote Access Solutions
Or, as @PhoneBoy wrote, Enable IP Pool NAT
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello
Wow this is new to us we taught SecuRemote was the app with all the functionally but we were wrong.
We have around 5 person with remote access could you recommend on of the product using your expertise.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When you install the VPN client you are given three choices:
- Endpoint Security VPN (requires an Access license or one of the SandBlast Agent ones)
- Check Point Mobile (requires either a Mobile Access license or licenses per above)
- SecuRemote (requires no license, but has significant restrictions)
I recently wrote up something on how to configure your gateway to support SecuRemote.
It also covers how to configure IP Pool NAT.
However, if you're talking only five users, depending on your license, you may already be covered.
Most modern licenses include Mobile Access for five concurrent users.
In which case, you can use Check Point Mobile and configure Office Mode.
R77.30 is VERY much End of Support at this point and I highly recommend upgrading to R80.40.
