|
Gary,
As far
as I know, Check Point would say 'PPTP with static NAT' is definately NOT
supported configuration. Below is a way I once made it work though. But
remember that you'll not be able to get technical support from Check Point with
this configuration because of their official stance.
Along
with your all configurations you have already;
Create
an object with the NATed PPTP server address.
Then,
allow a GRE service from above object going out.
Rationale behind this configuration is really weird.
You'll see a GRE packet from the PPTP server has a NATed address as its source
address. How this PPTP server know about this address? I can't confirm but I
believe PPTP server learned about it from the first response from its client.
Anyway, you just need to configure FW to allow NATed address coming from inside
your network to go out.
One
disclaimer: This might not work if MS PPTP has been changed with this regard in
the past year or so.
Hope
this help
Sun Yu
|
- [FW1] Can anyone say if PPTP and static NAT are definit... Gary Wilson
- RE: [FW1] Can anyone say if PPTP and static NAT ar... Byoung Sun Yu
- RE: [FW1] Can anyone say if PPTP and static NAT ar... Jean-Pierre Harvey
