Professional Documents
Culture Documents
Class B
172.16.0.0 172.31.255.255
Class C
192.168.0.0 192.168.255.255
Private addressing
Private addressing
can be used freely
cannot be used / routed on the internet
legal
legal
private
private
legal
legal
Hide NAT
The source IP addresses of the IP packets are
address translated
A full range of source IP addresses are mapped to
1 external legal source IP address !
TCP/UDP ports are used
private
private
legal
legal
Proxy ARP
NAT'ting behind a virtual IP address
IP address is not bound to the TCP/IP stack
Proxy ARP
How to activate PROXY ARP in 4.1/NG
Linux/Solaris
arp s virt_ip mac_ext_fw -pub
Nokia IPxxx
Use voyager to proxy arp
NT/W2K
local.arp in %FWDIR%\state directory (4.1)
a.b.c.d<TAB>xx-xx-xx-xx-xx-xx<CR><LF>
cpstop; cpstart
Automatic ARP configuration
Only NG
Only for automatic address translation rules
Fwparp.exe
Operation in 4.1
Forwarding
IN OUT
Eth0
Eth1
NAT
Eth2
Eth3
Operation in NG only
Forwarding
NAT
STATIC DESTINATION
NAT happens here,
if TRANSLATE
DESTINATION ON
CLIENT SIDE is enabled
IN OUT
Eth0
Eth1
NAT
Eth2
Eth3
Hide and static source NAT is
always performed here !!!
In FW-1/VPN-1 NG
Due to TRANSLATE DESTINATION ON CLIENT SIDE , no
route is needed.
Destination NAT on the Firewalls external IP address has
become possible.
Outgoing spoofing control is no longer enforced.
DE5281:i[40]: 10.1.1.101 -> 172.29.109.1 (TCP) len=40 id=61986 TCP: 3138 -> 80 ....A. seq=47147205
ack=5eff9753
DE5281:I[40]: 10.1.1.101 -> 172.29.109.1 (TCP) len=40 id=61986 TCP: 3138 -> 80 ....A. seq=47147205
ack=5eff9753
El90x3:o[40]: 10.1.1.101 -> 172.29.109.1 (TCP) len=40 id=61986 TCP: 3138 -> 80 ....A. seq=47147205
ack=5eff9753
El90x3:O[40]: 172.21.101.100 -> 172.29.109.1 (TCP) len=40 id=61986 TCP: 3138 -> 80 ....A. seq=47147205
ack=5eff9753
El90x3:i[1500]: 172.29.109.1 -> 172.21.101.100 (TCP) len=1500 id=9705 TCP: 80 -> 3138 ....A. seq=5eff9beb
ack=47147205
El90x3:I[1500]: 172.29.109.1 -> 10.1.1.101 (TCP) len=1500 id=9705 TCP: 80 -> 3138 ....A. seq=5eff9beb
ack=47147205
DE5281:o[1500]: 172.29.109.1 -> 10.1.1.101 (TCP) len=1500 id=9705 TCP: 80 -> 3138 ....A. seq=5eff9beb
ack=47147205
DE5281:O[1500]: 172.29.109.1 -> 10.1.1.101 (TCP) len=1500 id=9705 TCP: 80 -> 3138 ....A. seq=5eff9beb
ack=47147205
El90x3:i[48]: 172.29.109.1 -> 172.21.101.100 (TCP) len=48 id=9722 TCP: 2981 -> 80 .S.... seq=641928e1
ack=00000000
El90x3:I[48]: 172.29.109.1 -> 10.1.1.101 (TCP) len=48 id=9722 TCP: 2981 -> 80 .S.... seq=641928e1
ack=00000000
DE5281:o[48]: 172.29.109.1 -> 10.1.1.101 (TCP) len=48 id=9722 TCP: 2981 -> 80 .S.... seq=641928e1
ack=00000000
DE5281:O[48]: 172.29.109.1 -> 10.1.1.101 (TCP) len=48 id=9722 TCP: 2981 -> 80 .S.... seq=641928e1
ack=00000000
DE5281:i[48]: 10.1.1.101 -> 172.29.109.1 (TCP) len=48 id=63694 TCP: 80 -> 2981 .S..A. seq=4c33ba82
ack=641928e2
DE5281:I[48]: 10.1.1.101 -> 172.29.109.1 (TCP) len=48 id=63694 TCP: 80 -> 2981 .S..A. seq=4c33ba82
ack=641928e2
El90x3:o[48]: 10.1.1.101 -> 172.29.109.1 (TCP) len=48 id=63694 TCP: 80 -> 2981 .S..A. seq=4c33ba82
ack=641928e2
El90x3:O[48]: 172.21.101.100 -> 172.29.109.1 (TCP) len=48 id=63694 TCP: 80 -> 2981 .S..A. seq=4c33ba82
ack=641928e2
El90x3:i[293]: 172.29.109.1 -> 172.21.101.100 (TCP) len=293 id=9764 TCP: 2985 -> 80 ...PA. seq=67144d85
ack=4f47f94d
El90x3:I[293]: 172.29.109.1 -> 172.21.101.100 (TCP) len=293 id=9764 TCP: 2985 -> 80 ...PA. seq=67144d85
ack=4f47f94d
DE5281:o[293]: 172.29.109.1 -> 172.21.101.100 (TCP) len=293 id=9764 TCP: 2985 -> 80 ...PA. seq=67144d85
ack=4f47f94d
DE5281:O[293]: 172.29.109.1 -> 10.1.1.101 (TCP) len=293 id=9764 TCP: 2985 -> 80 ...PA. seq=67144d85
ack=4f47f94d
DE5281:i[257]: 10.1.1.101 -> 172.29.109.1 (TCP) len=257 id=65467 TCP: 80 -> 2985 ...PA. seq=4f47f94d
ack=67144e82
DE5281:I[257]: 172.21.101.100 -> 172.29.109.1 (TCP) len=257 id=65467 TCP: 80 -> 2985 ...PA. seq=4f47f94d
ack=67144e82
El90x3:o[257]: 172.21.101.100 -> 172.29.109.1 (TCP) len=257 id=65467 TCP: 80 -> 2985 ...PA. seq=4f47f94d
ack=67144e82
El90x3:O[257]: 172.21.101.100 -> 172.29.109.1 (TCP) len=257 id=65467 TCP: 80 -> 2985 ...PA. seq=4f47f94d
ack=67144e82
192.168.0.150
TimeOut 3600
srv_int_in 1
193.109.185.162
193.109.185.162
193.109.185.162
193.109.185.162
193.109.185.162
193.109.185.162
192.168.0.150
193.109.185.162
3665
C11 49
srv_int_out 1
21
21
21
21
21
21
3665
21
193.109.185.162 21
c12 1046116859 C13 0
6
0001c001
C14 4116303811 C15 1974
00806080
cl_int_in 0
Rule 8
cl_int_out 0
195.207.89.244
6
192.168.0.150
6
192.168.0.150
6
193.109.185.162
6
13896
192.168.0.150
3665
3665
192.168.0.150
3665
3665
192.168.0.150
3665
21
192.168.0.150
3665