NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] Manual NATs on FW-1 NG


  • To: [email protected]
  • Subject: Re: [FW-1] Manual NATs on FW-1 NG
  • From: Michael Martin <[email protected]>
  • Date: Thu, 7 Aug 2003 08:12:45 -0700
  • Reply-to: Mailing list for discussion of Firewall-1 <[email protected]>
  • Sender: Mailing list for discussion of Firewall-1 <[email protected]>
  • Thread-index: AcNc7aJeC46Hq61STa2ReG2oABMkIgAB04Qk
  • Thread-topic: Manual NATs on FW-1 NG

?
Proxy ARP is never automatic when using manual NAT.  You need to create a local.arp file in the $FWDIR/state directory and add ARP entries there.  The syntax is just IP <tab> MAC <CR>.  Not sure why this isn't documented more clearly by Checkpoint, especially since this was the default requirement for all NAT pre-NG.

________________________________

From: Mailing list for discussion of Firewall-1 on behalf of Kevin Barrass
Sent: Thu 8/7/2003 6:37 AM
To: [email protected]
Subject: Re: Manual NATs on FW-1 NG



Just to add to this when I type fw ctl arp it is showing a proxy arp for
address iam translating to, but if I add the NATs manualy there is no proxy
arp.

Cheers

Kev
>  -----Original Message-----
> From:         Kevin Barrass
> Sent: 07 August 2003 14:02
> To:   '[email protected]'
> Subject:      Manual NATs on FW-1 NG
>
>
> Hi
>
> I have setup a test firewall on windows2000 pro with FW-1 NG FP3 I have
> one PC on the inside network if I set up the PC on the inside NAT hiden
> behind the firewall IP its ok but if I try to use auto or manual NAT it
> wont work I don't have anyything like tcpdump on the PC to see what is
> happening, I looked through previous postings and on phoneboys website and
> tried static routes as below
>
> Route -p add outsideaddress inside address
>
> And this still did not work although I thought NG did all this and the
> proxy arps for you,
>
> Any advise much apreciated.
>
> Regards
>
> Kev
>
> **********************************************************************
> Kevin Barrass
> Network Support Officer
> South West Yorkshire Mental Health NHS Trust
> Information Services
> Fieldhead, Ouchthorpe Lane
> Wakefield, WF1 3SP
> * 01924 327551
> * [email protected]
> *********************************************************************
> Providing IT services to:
> South West Yorkshire Mental Health NHS Trust
> Eastern Wakefield Primary Care NHS Trust
> Wakefield West Primary Care NHS Trust
>

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================



=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.