Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Surya24d
Explorer

Dnat issue in the firewall

Hi, 

I'm running checkpoint firewall with R81 version in cluster mode.

My servers and security gateway subnets are different.

When I'm trying to use destination nat from  outside interface eth1-03 to eth1-01(servers lan interface) http traffic is accepted in the logs but web page not opening. 

 

Servers interface 10.179.8.0/25 with gateway 10.179.8.1 connected to l3 switch.

From there connected to Eth1-01 interface ip 10.179.8.125

Cluster on eth1 interface is 10.179.8.123 and 124 and vip 126

Security gateway interface on mgmt port is 1.179.8.194/28 gateway 10.179.8.193

Public ip interface on eth1-03 interface with 218.248.240.66/26

Nat ip 218.248.240.65/32. And server ip 10.179.8.81/32.

Traffic has been accepted and nat translation also fine.

0 Kudos
2 Replies
_Val_
Admin
Admin

See if the routing works both ways and also ARPs. The only reason it is not working is about connectivity. Run traces on GW side and server side to see where it's failing

0 Kudos
Chris_Atkinson
Employee Employee
Employee

I agree with @_Val_ but to be sure is the server really using a /32 netmask does it have multiple NICs?

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events