NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW1] Natting two 10.0.0.0 networks



Greetings!

"Varnam, Gary" schrieb:

> They cannot perform any NAT translation. What I propose is all packets
> from
> the external interface from network 10.30.33.0 be translated to
> 172.21.21.0
> and vice Vera.
> I have two objects up
> Contractor_Original with ip address 10.30.33.0 mask 255.255.255.0 and
> Contractor_NAT with ip address 172.21.21.0 mask 255.255.255.0
> In the rule base I have allowed both objects to telnet to host, on the
> NAT
> Rules I have said
> Source of Contractor_Original change to Contractor_NAT
> destination of Contractor_NAT change to Contractor_Original.
> The packet is accepted by the firewall but NAT does not occur.
>

You have routing set up properly (remembered the "Routing-before-NAT")?
If you do a SNOOP on the interfaces in question - what do you see?

Bye
    Volker

--

Volker Tanger  <[email protected]>
 Wrangelstr. 100, 10997 Berlin, Germany
    DiSCON GmbH - Internet Solutions
         http://www.discon.de/




================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.