NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [FW1] what occurs first NAT or RULEBASE



Title: RE: [FW1] what occurs first NAT or RULEBASE
You are in fact correct Tim.  As traffic enters the firewall from the external interface it is processed in the following order:
 
Encryption
Anti-spoofing
Rule base
NAT

Hope this helps,
Noel T. Stafford
CCSA, CCSE, CCFE
Network Engineer
IT - Data Communications Group
Western Wireless Corporation
[email protected]

-----Original Message-----
From: Tim Wolfe [mailto:[email protected]]
Sent: Wednesday, June 20, 2001 12:40 PM
To: 'Shah, Nishith'; 'Jabal P Raval'
Cc: '[email protected]'
Subject: RE: [FW1] what occurs first NAT or RULEBASE

That seems incorrect to me.  I think you may be thinking of NAT before routing.  If NAT occurred before security policy, why would you have a web server in a DMZ with a private IP NATed to a public IP and allow incoming requests to the public IP?  It seems like you'd have to allow incoming requests to the private IP to make that work, if CP operates the way you think it does...  Just my .02, I'm not 100% sure.

Thanks,

--Tim

===============================================
Timothy M. Wolfe                CCSE/NSA/CCNA
Sr. Security Engineer          
[email protected]
InfoGroup Northwest            x108
===============================================

 

-----Original Message-----
From: Shah, Nishith [mailto:[email protected]]
Sent: Tuesday, June 19, 2001 7:17 AM
To: 'Jabal P Raval'
Cc: '[email protected]'
Subject: RE: [FW1] what occurs first NAT or RULEBASE

Always NAT first.


A CCSA question.

-----Original Message-----
From: Jabal P Raval [mailto:[email protected]]
Sent: Monday, June 18, 2001 4:53 PM
To: [email protected]
Subject: [FW1] what occurs first NAT or RULEBASE




in checkpoint firewall-1 4.1, what occurs first, when a packet comes in, rulebase
checking or address translation?

Thanks/.



================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.