3
Configuring IP71
82
Nokia IP71 User Guide
through a hide translation (e.g. outbound traffic will appear to be coming
from 204.32.38.1).
Never translate any interface on your firewall. A range object is created to
define the Internal net in a way that excludes the Firewall’s internal interface.
The rules are processed in-order. This means that the HTTP server, while it is
covered by both rules 1 and 2, will be translated to 192.168.1.10 through a
static translation and not 204.32.38.1 through a hide translation. This also
means that if someone surfs the web from the web server, it will appear to be
coming from the firewall.
Configuring Routing and ARP Entries
Configure the Routing and ARP entries in your IP71.
To configure routing and ARP entries,
1.
Set up a proxy ARP for the legal IP address.
This ensures that on the data link level, the traffic arrives at the firewall.
2.
Set up a route on the firewall itself for the static address translation.
This ensures that the traffic eventually is delivered from the correct
interface on the firewall.
In this case, set up:
1.
A proxy ARP for 204.32.38.10
2.
A static route for 204.32.38.10
Installing the Security Policy
When changes are made to the security policy or NAT rules, reinstall the
security policy for the changes to take effect. Install the security policy and
test to ensure that each rule is being enforced correctly by observing the logs
while performing actions that are permitted and not permitted.
Summary of Contents for IP71
Page 1: ...IP71 User Guide version 2 0 N450794001 Rev A October 2002 ...
Page 4: ...iv Nokia IP71 User Guide ...
Page 94: ...4 Configuring a VPN 94 Nokia IP71 User Guide ...
Page 102: ...A Obtaining a Check Point License 102 Nokia IP71 User Guide ...
Page 108: ...B Technical Specifications 108 Document Title Variable ...