Using Hide NAT.  

EXTERNAL        ANY     ANY     ->      INTERNAL        ORIG    ORIG

The External IP address is a valid IP address of course...

Joe

> -----Original Message-----
> From: Darly Coupet [mailto:[EMAIL PROTECTED]]
> Sent: Tuesday, July 11, 2000 2:56 PM
> To: Joe Voisin; [EMAIL PROTECTED]
> Subject: RE: [FW1] VPN - NAT and Encryption
> 
> 
> Joe,
> 
> Private Net NAT(hide) --- FW1 ----Internet---- FW1--- NAT(hide) 
> >> Private Net
> 
> 
> Are you using Hide NAT to the External Interface or other Valid IP ?
> Is the Encryption/Decryption taking place at the Valid IP or 
> Private Network ?
> Sould the Encryption domain for each network be the External 
> or Valid IP or
> the Private Network.
> 
> This is a FW-1 Gateway VPN-1 to FW-1 Gateway VPN-1 
> 
> Thanks
> 
> Darly 
> 
> At 02:33 PM 7/11/2000 -0400, Joe Voisin wrote:
> >I am using IKE with 3DES/MD5 no problem through my LinkSys 
> NAT Router...
> >Will not work with FWZ encryption.  I would also think that 
> your router/NAT
> >would have to support IPSec to some degree.. even if it's just IPSec
> >Passthru...
> >
> >I haven't played with this with other NAT based routers but 
> I would think
> >that the same applies...
> >
> >> -----Original Message-----
> >> From: Darly Coupet [mailto:[EMAIL PROTECTED]]
> >> Sent: Tuesday, July 11, 2000 2:23 PM
> >> To: "Firewall-1 (E-mail)"@onus.us.checkpoint.com;
> >> [EMAIL PROTECTED]
> >> Subject: [FW1] VPN - NAT and Encryption
> >> 
> >> 
> >> 
> >> Firewallers,
> >> 
> >> Does Firewall 4.1 support the following configuration?
> >> 
> >> Private Network NAT --- FW1 ----Internet---- FW1--- NAT 
> >> Private Network
> >> 
> >> Can I use Hide NAT for each private network?
> >> 
> >> What is the recommended encryption methods?
> >> 
> >> Thanks for your comments.
> >> 
> >> Darly
> >> 
> >> 
> >> ==============================================================
> >> ==================
> >>      To unsubscribe from this mailing list, please see the 
> >> instructions at
> >>                http://www.checkpoint.com/services/mailing.html
> >> ==============================================================
> >> ==================
> >> 
> >
> >
> 


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to