I assume you have a static route on the firewall and an entry in local.arp?

-----Original Message-----
From: Doug Crouch [mailto:[EMAIL PROTECTED]]
Sent: 10 January 2003 17:00
To: [EMAIL PROTECTED]
Subject: [FW-1] What the NAT is going on ?

Hello

Anybody got any ideas on how I can diagnose this little problem ...

I have Checkpoint Firewall v4.1 running on an NT box

For example, if the address of my router is 190.100.150.1, and I have a
range of valid public IP addresses up to 190.100.150.15

-------------------------
Private address '10.0.0.1' Static NAT '190.100.150.2'

Ping 190.100.150.1 -> Success

Firewall log 'Accept Action' src: '10.0.0.1' dest : '190.100.150.1' proto :
'ICMP' Xlatesrc : '194.200.250.2' Xlatedest : '190.100.150.1'

--------------------------
Private address '10.0.0.2' Static NAT '190.100.150.3'

Ping 190.100.150.1 -> Fail

Firewall log 'Accept Action' src: '10.0.0.2' dest : '190.100.150.1' proto :
'ICMP' Xlatesrc : '194.200.250.3' Xlatedest : '190.100.150.1'

--------------------------

So according to the Firewall the action is being accepted but the packet is
getting lost somewhere !

I've tried flushing the arp cache on the router, but I don't know where else
to look for problems.

Thanks
Doug

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================


*************************************************************************************************************************************************************************************************************************
This is an email from the ICM Computer Group of Companies and is confidential. If you 
are not the intended recipient you must not disclose or use the information but please 
delete the email as soon as possible.
If you have received this email in error please notify our mail manager at 
[EMAIL PROTECTED]  Note that this is NOT the address of the person who sent 
this mail to you but a general administrative address.  If you wish to reply to the 
sender of this message, use the "Reply" function built into your email software.
Any views in the email are those of the sender only and not those of the ICM Computer 
Group of Companies. This email is not intended to be contractually binding.
As part of conducting its business, ICM may monitor and record emails and their 
contents passing through their network under the Telecommunications (Lawful Business 
Practices)and(Interception of Communications) Regulations 2000.
Although we have checked this e-mail for viruses, it is not guaranteed to be virus 
free and it is your responsibility to scan the message and attachments prior to 
opening them.  We do not accept any responsibility for the consequences of passing on 
any virus.
For further information please visit the ICM Computer Group plc website at 
<http://www.icm-computer.co.uk/>
Version 1.4 2002 ICM Computer Group plc
*************************************************************************************************************************************************************************************************************************

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to