Title: NAT and Security
Ask yourself this question....I'm on the internet and want to access the web server which interface will first answer me? Of course the external one and after the firewall does that the NAT.
Option A is what you want to do, but If you can put your webserver_int in a DMZ go for it
In Checkpoint 4.1 don't forget the local.arp and adding a route
In NG NAT is done automaticly
 
 
----- Original Message -----
Sent: Friday, April 12, 2002 6:12 AM
Subject: [FW-1] NAT and Security

Dear All,

I have one question about translation address and security.

If I have the following situation:

webserver_int - 192.168.10.10
webserver_ext - 200.200.201.12 (www.ez.com)

I have created the NAT for those address, and I will have to configure the security.

At the security tab must I configure wich way, A or B:

A)
source: any
Destination: 200.200.201.12 (external)
Service: http
Action: Accept

Or

B)
source: any
Destination: 192.168.10.10 (internal)
Service: http
Action: Accept

Is necessary to create a rule with the internal, external or both address?

Thanks a lot!!!
Best Regards for all.



Jo�o Coimbra --> Gest�o T�cnica - MCSE / ASE
--> [EMAIL PROTECTED]
-------------------------------------------------------------------------------
Fone: +55 11 3365-0305 - Fax: +55 11 3365-0319
-------------------------------------------------------------------------------
EZTrade --> Transformamos seu business em e-business
--> www.eztrade.com.br

Reply via email to