- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Routing vs NAT help - please be gentle
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Routing vs NAT help - please be gentle
We have a Checkpoint R81.20 Gaia Security Gateway that is also our firewall and router. The Management server for the Security Gateway is a Cloud-1 controller. The firewall is running Gaia OS on a VM on ESXi 8.
I have the network divided into VLANs and then they all access each other through the R81.20 firewall. Each VLAN has a network interface on the gateway with a unique subnet. Everything is currently NATed between each network. I would like to find a way to route between the networks instead of NATing between the networks. For example if I look at SSH logs for connections between a client and a server, all of the client IPs show as coming from the gateway IP and not the IP Address of the client in the other VLAN.
I understand that this is probably a bit of a basic question and that if I don't understand routing vs NAT completely, I should find a consultant, which I may do. However, please let me know if what I describe next is totally wrong or if I am headed down the correct path.
Can Gaia act as our firewall for clients in the VLANs to access the internet AND allow me to route between the VLANs without having to use NAT?
Any help is most apprecaiated.
_Rob
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, this is possible, it's just a matter of configuring NAT correctly.
You will need to define some manual NO NAT rules (where original source/destination are specified and translated source/destination are "Original").
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Wow, the man, the myth, and the legend himself! Thank you @PhoneBoy !
I will search for those settings and test some things out with some unpopulated VLANs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
An example of some NO NAT rules actually appears in the Demo Mode policy (though I added an object to it).
You add them above the auto-generated rules, as shown here.
