- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Port Forwarding in Checkpoint
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Port Forwarding in Checkpoint
Good Day
I am from a Fortinet background and currently working more on Checkpoint in the other there is what we call virtual IPs aka Port Forwarding i know we have Manual NAT in checkpoint but in the instance where i have multiple web servers and one static public IP provisioned by ISP say with a /30 subnet mask how can i go about Manual Nat in checkpoit say for expample my external IP is 178.xx.xx.1/30 and my LAN is 10.1.10.0/24 where i have web server 10.1.10.10:443 and another 10.1.10.11:8443 how can I achieve accessing this from public facing i have decided to change the ports due to 443 being used by another web server hence using 8443 for another server on the LAN.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You have the notion of original port and translated port if this answers your question.
You can publish 8443 as original port and put 443 as translated port.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sk60343: How to Troubleshoot NAT-related Issues
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Should be pretty easy. Just create manual static nat rule in smart console and make sure the info is right (original src, dst, translater src, dst and ports).
Ping me if you need help.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Think of it this way and as trivial as this example is, I always give this to people. So say your friend wants to rdp into your computer at home, all you would need to do is create a "rule" in your home router that says from external to your internal IP on dst port 3389, thats it.
Makes sense?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes that i all understand i was wondering on checkpoints GAIA in this instance i know about the manual nat I was just wondering how i can workaround if i have multiple hosts that need to be publicly accessible and there are accessed through port 443 so i will explore original port and translated port.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I see what you mean. For that, yea, you may need to change the port.
