Hello all,

at the moment I have a number of NAT rules that state

orig src          orig  dst               orig   service                  translated 
src     translated destination              translated service
objecta  ->    grpobject                   Any                    |          
hideobject                original                              original
objectb  ->    grpobject                   Any                    |          
hideobject                original                              original
objectc  ->    grpobject                   Any                    |          
hideobject                original                              original

etc

and that wrks fine

what I would like to do is have

orig src          orig  dst               orig   service                  translate 
src     translated destination              translated service
ANY    ->         grpobject                 ANY              |            hideobject   
                original                                  original

However when I verify the rule base I receive  message saying

"Security and Address Translation  Policy Verification:
Invalid <Any> in  Source  of Address Translation Rule 98.
 <Any> is valid only if the matching Translated column is <Original>.
"

I am not sure why I can't define a NAT rule like this ?

any help much appreciated

Kind regards

Josh

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to