Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RobertZdunek2
Explorer

Hairpin NAT alternatives

Hi CheckMates,

We've successfully deployed hairpin NAT described here: sk110019 - How to configure NAT Loopback (Hairpin NAT / NAT Reflection) on Check Point Security Gate... in our production environment. Works well, but the main disadvantage of that solution is that the server does not know who talks to it, as all traffic is translated to some gateway interface. Is there any other solution for LAN devices to talk to server over Public IP, that would keep source original IP, so the logs on the server shows who is really communicating?

 

Thanks,

Robert

0 Kudos
1 Reply
emmap
Employee
Employee

It becomes a networking problem. If the gateway isn't in path to de-NAT the reply packets, the client doesn't know why it's receiving those packets. If the C2S connection isn't NAT'd to the gateway IP, the reply packet won't get to the gateway to deNAT it. The best solution is to not have to NAT it at all, perhaps through name resolution or another mechanism.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events