[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [FW1] Natting two 10.0.0.0 networks
Greetings! "Varnam, Gary" schrieb: > They cannot perform any NAT translation. What I propose is all packets > from > the external interface from network 10.30.33.0 be translated to > 172.21.21.0 > and vice Vera. > I have two objects up > Contractor_Original with ip address 10.30.33.0 mask 255.255.255.0 and > Contractor_NAT with ip address 172.21.21.0 mask 255.255.255.0 > In the rule base I have allowed both objects to telnet to host, on the > NAT > Rules I have said > Source of Contractor_Original change to Contractor_NAT > destination of Contractor_NAT change to Contractor_Original. > The packet is accepted by the firewall but NAT does not occur. > You have routing set up properly (remembered the "Routing-before-NAT")? If you do a SNOOP on the interfaces in question - what do you see? Bye Volker -- Volker Tanger <[email protected]> Wrangelstr. 100, 10997 Berlin, Germany DiSCON GmbH - Internet Solutions http://www.discon.de/ ================================================================================ To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================================================
|