Thursday 2 February 2017

investigating NAT issues on checkpoint firewalls

In Network Objects (bottom left)
Right click Nodes -> More -> Query Objects
Refine by: Search by IP

Double click on the object and check the NAT section for auto NAT

Also you can do Actions -> Where used -> Active policy
Look for any manual NAT's here

Try the traffic while watching the logs in the tracker
You can add the columns xlatesrc and NAT rule into the tracker
Also you can double click the log entry and get more details on the NAT rule and xlated source

Auto NAT's are processed first
Manual NAT's second


No comments:

Post a Comment