We are doing exactly that with all of our public access servers. If you
check the box "Exportable" the object will be available through the secure
remote client, assuming the proper rules are implemented. You will need an
LMhosts file on the Secure remote machine with the NATed addresses instead
of the public ones. Then when you try to connect to the netbios name it will
use the private address, Secure Remote will recognize that is an exportable
object and your traffic will be allowed to pass. The key is to use the
internal NATed address in the LMhosts file, otherwise it will never work.
Ken Claussen MCSE CCNA CCA
IT Coordinator
Retail Planning Associates
(614) 564-1000 x208
-----Original Message-----
From: Joerg Oertel [mailto:[EMAIL PROTECTED]]
Sent: Wednesday, October 25, 2000 9:08 AM
To: [EMAIL PROTECTED]
Subject: [FW1] SecuRemote into NATed network
Hi gang,
I have a general question.
We're doing static NAT for the host HERBERT we're trying to telnet to.
We're doing hide NAT for the complete class C network HERBERT belongs
to.
Without SecuRemote we can access HERBERT from the internet (as long as
a appropriate rule is implemented).
192.168.1.1
SecuRemote Client --------------- FW-1 4.1 SP2 ------------HERBERT
|
|
|
Other hosts
(192.168.1.x)
Someone told me that it's not possible to use Securemote to connect to
a host that is in a NATed network. Is that true?
Kind regards,
J�rg
// pallas GmbH ............ Joerg Oertel ...........
Hermuelheimer Str. 10 System engineer
D-50321 Bruehl, Germany [EMAIL PROTECTED]
phone +49-(0)2232-1896-0
http://www.pallas.de fax +49-(0)2232-1896-29
........................................................
============================================================================
====
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
============================================================================
====
================================================================================
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
================================================================================