- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Many to One NAT
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Many to One NAT
Hi All
Is that possible in checkpoint security gateway r81.10 to do the below many to one NAT IP ?
Src: 172.16.16.0/24
Dest: 192.168.25.1/32
Src NAT: 10.10.15.2
Dest NAT : Original
Thanks,
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, just make sure it is a HIDE NAT.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@AkosBakos @the_rock @CaseyB I just saw the red H sign under the translated Source and and just right click on it and on the translated source NAT Method to Hide works I didn't know this before Thank you guys you are a real life saver.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Ihenock1011
Maybe I misunderstood something but NAT is for this:
Akos
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@AkosBakos Yes but as below
Original Src: 172.16.16.0/24
Original Dest: 192.168.25.1/32
Translated Src: 10.10.15.2
Translated Dest : Original
The checkpoint throws an error "Invalid object in source of address translation rule # The range size of Original and Translated column must be the same."
The original source is network subnet /24 and the Translated source is single host.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you choose hideNAT?
Can you show a screenshot of the rule?
A
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As @CaseyB make it hide nat, or to overcome it, maybe use address range, that usually works.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@AkosBakos @the_rock @CaseyB I just saw the red H sign under the translated Source and and just right click on it and on the translated source NAT Method to Hide works I didn't know this before Thank you guys you are a real life saver.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You are welcome!
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Great! Btw, I did try with address range, but complained about the same, so guys were 100% right, you have to use hide nat.
Glad you got it.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, just make sure it is a HIDE NAT.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@CaseyB How do I do that. My understanding is HIDE NAT will hide behind the gateway or specific address. However mine is it will destined to a host IP
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Let me test this in the lab now and I will send you a screenshot.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Andy, check my screenshot. It works wit /32 and with simple host object as well.
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I did check it, but thats NOT how @Ihenock1011 wants it lol
Let me see if I can make it work how he described.
Andy
