Firewall Wizards mailing list archives

RE: NAT Based on Service with only one legal IP


From: "manatworkyes moderator" <devekboy () hotmail com>
Date: Wed, 21 May 2003 15:05:53 +0000

As far as i know, Starting at Check Point NG FP3, it can be done using the NAT rulebase as follows (make sure that NAT on client side properties are checked):

rule 1: from internal net to internal net - do not NAT .
rule 2: from internal net to any hide behind 0 .
rule 3. from all IPs range any to any service ftp - translate to FTP server . rule 4. from all IPs range any to any service http - translate to HTTP server.

Hope it helps,
--Devek

-----Original Message-----
From: firewall-wizards-admin () honor icsalabs com
[mailto:firewall-wizards-admin () honor icsalabs com] On Behalf Of W. Builder
Sent: Tuesday, May 20, 2003 5:43 PM
To: firewall-wizards () honor icsalabs com
Subject: [fw-wiz] NAT Based on Service with only one legal IP


Dear Gurus

Service based NAT with only one legal IP can be done
with Checkpoint FW-1 NG but not for dynamically
allocated legal IP

http://www.phoneboy.com/fom-serve/cache/86.html

Are there any other non-CheckPoint firewall s/ware
products or appliances that can do this with both
one legal static IP ? With  one dynamically assigned
legal IP?

Many thanks
W.Builder

_________________________________________________________________
Tired of spam? Get advanced junk mail protection with MSN 8. http://join.msn.com/?page=features/junkmail

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: