Great Circle Associates Firewalls
(July 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Firewall-1 and Address Translation
From: Patrik Backstrom <pb @ techno . org>
Date: Fri, 25 Jul 1997 09:20:02 +0200 (MET DST)
To: firewalls @ greatcircle . com

Hi!

Let's say i have a couple of c-classes behind my Firewall-1, and i wan't
to translate those to public IP's whenever they connect to the outside
world. Can i hide all of those c-classes behind, say, 128 public IP's?

If i in Network Objects -> Network Properties -> Address Translation
select Add Automatic Address Translation Rules, Translate Method Static,
and select the same First Valid IP for all of those c-classes, will it
work? Ofcourse, every IP cannot connect to the outside world at the same
time, but will Firewall-1 remove the assignment from the hidden ip to the
public ip, after a short period of inactivity time?

Ofcourse, i can hide the whole c-class behind one IP, using the Hidden
Translate Method, but then you will loose some functionality.

/pb

 ---------------------------------------------------------------------
  Patrik Bäckström (BOFH)   Phone........: +46-(0)706-661928
  Hjalmar Bergmans gata 50  Homepage.....: http://warp.techno.org/~pb
  422 52 Hisings Backa      E-Mail.......: pb @
 techno .
 org

  PGP Pub Key......: http://warp.techno.org/~pb/pgpkey
             \.....: finger pb @
 warp .
 techno .
 org
 ---------------------------------------------------------------------



Follow-Ups:
Indexed By Date Previous: Re: Firewall-1 Limitations...
From: Martin Khoo <martin @ nii . ncb . gov . sg>
Next: Re: standard policy on fw-1
From: Vinci CHOU <vkmchou @ HK . Super . NET>
Indexed By Thread Previous: Re: [FW1] Question: TCP port used by MS SNA server
From: Jay Aho <jaya @ netrex . com>
Next: Re: Firewall-1 and Address Translation
From: Jamie Thain <jthain @ cat . bbsr . edu>

Google
 
Search Internet Search www.greatcircle.com