Re: Applying NAT Rules in Firewall-1 To External Targets Only?

Re: Applying NAT Rules in Firewall-1 To External Targets Only?

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Re: Applying NAT Rules in Firewall-1 To External Targets Only? Greg Hennessy 09-01-2006
Posted by Greg Hennessy on September 1, 2006, 3:29 am
If you were  Registered and logged in, you could reply and use other advanced thread options
wrote:

>> The 1st nat rule would would be something like
>>
>> dmz-nets dmz-nets any original original any
>
>That's a useful shortcut, thanks!
>
>How do you write the NAT rule in order to have Firewall-1's anti-spoofing
>features not complain about the packet when it arrives on a DMZ interface?

As long as you have client side NAT ticked in the global properties and
anti spoofing properly configured in the gateway's topology it will figure
it out.


>As soon as I turn on anti-spoofing on the DMZ interface, I see packets that
>comply with the ruleset succeed in the log and pass through the firewall to
>the DMZ interface. But then there is a second duplicated message in the
>log with a reject that complains the packet violates the anti-spoofing
>policy.


Sounds like you dont have it properly configured on every interface.


Getting the topology right is essential.


Recommend taking a trawl through the fw1 wizards mailing lists archive and
the forums on www.cpug.org for other useful information regarding starting
out with fw1.




greg
--
Müde lieg ich lieg in der Scheisse,
und niemand weiss, wie ich heisse.
Es gibt nur einen, der mich kennt,
und mich bei meinem Namen nennt.

Posted by Will on September 3, 2006, 4:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> >As soon as I turn on anti-spoofing on the DMZ interface, I see packets
that
> >comply with the ruleset succeed in the log and pass through the firewall
to
> >the DMZ interface. But then there is a second duplicated message in the
> >log with a reject that complains the packet violates the anti-spoofing
> >policy.
>
> Sounds like you dont have it properly configured on every interface.
>
> Getting the topology right is essential.

Our network is this simple:

External interface is configured with anti-spoofing set to "Others"
Three DMZ interfaces are each configured with anti-spoofing set to "This
Network"

That exactly matches the topology suggested by the Firewall-1 online
documentation as well. Did we do something wrong? When we configure it
this way, we get anti spoofing log messages when the packets get to the DMZ
interface.

Someone else mentioned to me that Firewall-1 is routing the packet to the
DMZ interface and only then performing NAT. Is that right? In that case
don't you need to configure the DMZ interfaces to work with both the before
NAT and after NAT versions of the IP expected at each DMZ?

--
Will



Similar ThreadsPosted
Applying iptables firewall rules: iptables-restore: line 19 failed August 31, 2005, 2:58 am
Protecting internal MS Certificate Server with Firewall1 NG FP3 May 11, 2005, 12:29 am
NAT Not Always Applying February 21, 2007, 4:56 am
where is my external dns ? June 11, 2006, 7:55 am
PIX VPN using the external IP addresses September 6, 2005, 5:35 pm
Forward to external ip March 10, 2006, 7:05 am
Question on internal/external IPs December 10, 2004, 2:18 pm
Problems after external IP change... April 21, 2005, 10:52 am
External management on a netscreen-5 May 26, 2005, 1:23 pm
External management on a netscreen-5 May 26, 2005, 1:23 pm

The site map in XML format XML site map

Contact Us | Privacy Policy