- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Dnat issue in the firewall
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dnat issue in the firewall
Hi,
I'm running checkpoint firewall with R81 version in cluster mode.
My servers and security gateway subnets are different.
When I'm trying to use destination nat from outside interface eth1-03 to eth1-01(servers lan interface) http traffic is accepted in the logs but web page not opening.
Servers interface 10.179.8.0/25 with gateway 10.179.8.1 connected to l3 switch.
From there connected to Eth1-01 interface ip 10.179.8.125
Cluster on eth1 interface is 10.179.8.123 and 124 and vip 126
Security gateway interface on mgmt port is 1.179.8.194/28 gateway 10.179.8.193
Public ip interface on eth1-03 interface with 218.248.240.66/26
Nat ip 218.248.240.65/32. And server ip 10.179.8.81/32.
Traffic has been accepted and nat translation also fine.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
See if the routing works both ways and also ARPs. The only reason it is not working is about connectivity. Run traces on GW side and server side to see where it's failing
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree with @_Val_ but to be sure is the server really using a /32 netmask does it have multiple NICs?
