No.
By design, DNAT, does not accept inbound connection attempts.

-K


-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[EMAIL PROTECTED] On Behalf Of Sascha
Picchiantano
Sent: Thursday, September 16, 2004 9:28 AM
To: [EMAIL PROTECTED]
Subject: [FW-1] NAT question


Hi there,

if we have one public IP address and use that to Hide NAT our internal
network, can we use that same IP address for a additional Static NAT
rule?

e. g. we have on public IP, need to hide our network behind it and still
need to talk to a specific internal machine (and only on a specific
port) from the Internet. We tried it by simply adding a static NAT rule
to the already existing automatic Hide NAT rule, but it does not seem to
work. The static NAT rule translates the public IP address and service
XYZ to the internal IP address.

NAT rules:
1. internal_Server -> StaticNAT on public IP 1.1.1.1, Service XYZ
2. internal_LAN   ->  HideNAT on public IP 1.1.1.1

On cheap firewalls you would call this Port Forwarding.

It does not work here. Is it even possible?

Thanks,
Sascha

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to