<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bi-directional NAT is not working post VMSS deployment in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99980#M2000</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="49E78284-54B3-4602-89A3-A97AAB31A534.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8571i9CA1223C1105777D/image-size/large?v=v2&amp;amp;px=999" role="button" title="49E78284-54B3-4602-89A3-A97AAB31A534.jpeg" alt="49E78284-54B3-4602-89A3-A97AAB31A534.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;that‘s the route you need to add&lt;/P&gt;</description>
    <pubDate>Fri, 23 Oct 2020 15:24:35 GMT</pubDate>
    <dc:creator>Matthias_Haas</dc:creator>
    <dc:date>2020-10-23T15:24:35Z</dc:date>
    <item>
      <title>Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99555#M1985</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For some reason the bi-directional NAT is not working for one of our Destination Natted traffic in VMSS deployment (2 instances) . Return traffic from destination is not able to connect to the original src.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;R80.40 - Build 105&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing something ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rule -&lt;/P&gt;&lt;P&gt;Original Src- 10.22.x.x-23 ,&amp;nbsp;10.22.y.y-23 ( Network Group - consisting of Network )&lt;/P&gt;&lt;P&gt;Original Dst - 10.22.8.40&lt;/P&gt;&lt;P&gt;Original Port - 443&lt;/P&gt;&lt;P&gt;Xlated Src - Original&lt;/P&gt;&lt;P&gt;Xlated Dst -&amp;nbsp;10.22.133.10 (Type Static)&lt;/P&gt;&lt;P&gt;Xlated Port- Original&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log -&lt;/P&gt;&lt;P&gt;Cann't see - &lt;STRONG&gt;Additonal Nat Rule -1 ,&amp;nbsp;&lt;/STRONG&gt; which generally comes in traffic .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; --- Any help , will be highly appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 08:54:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99555#M1985</guid>
      <dc:creator>Abhishek_Singh1</dc:creator>
      <dc:date>2020-10-20T08:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99573#M1987</link>
      <description>&lt;P&gt;Do you see nating in fw monitor?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 10:42:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99573#M1987</guid>
      <dc:creator>Rohit_Raut</dc:creator>
      <dc:date>2020-10-20T10:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99576#M1988</link>
      <description>&lt;P&gt;&lt;STRONG&gt;R80.40 - Build 105&lt;/STRONG&gt; and which Jumbo HFA ?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 11:33:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99576#M1988</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-20T11:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99577#M1989</link>
      <description>HOTFIX_R80_40_JUMBO_HF_MAIN Take: 78</description>
      <pubDate>Tue, 20 Oct 2020 11:35:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99577#M1989</guid>
      <dc:creator>Abhishek_Singh1</dc:creator>
      <dc:date>2020-10-20T11:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99645#M1990</link>
      <description>&lt;P&gt;Did you read the help with bi-directional NAT?&lt;BR /&gt;This option is only relevant for automatic NAT rules.&lt;/P&gt;
&lt;P&gt;In any case, not sure I understand what is happening here.&lt;BR /&gt;Can you be far more explicit about what you expect, what is actually happening, etc?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 00:56:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99645#M1990</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-21T00:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99784#M1991</link>
      <description>&lt;P&gt;do you see a drop/out of state&amp;nbsp; for the return packet (Source:&amp;nbsp;&lt;SPAN&gt;10.22.133.10,&amp;nbsp; Destination: 10.22.x.x-23 ,&amp;nbsp;10.22.y.y-23) ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 06:49:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99784#M1991</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-10-22T06:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99825#M1992</link>
      <description>&lt;P&gt;This is observed for&amp;nbsp;&lt;STRONG&gt;EAST-to-WEST&amp;nbsp;&lt;/STRONG&gt;return traffic .&lt;/P&gt;&lt;P&gt;Basically , the incoming packet from CP internal LB is coming to 1 instance of GW (eth1) and the return traffic is coming on the other GW (eth1) via the CP internal LB .&lt;/P&gt;&lt;P&gt;I did added the&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;LocalGatewayInternal&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;( Xlated Source - type Hide NAT)&amp;nbsp;&lt;/EM&gt;but still no luck .&lt;/P&gt;&lt;P&gt;Note - the interesting traffic over here is&amp;nbsp;&lt;STRONG&gt;FTP - Passive &lt;/STRONG&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 12:43:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99825#M1992</guid>
      <dc:creator>Abhishek_Singh1</dc:creator>
      <dc:date>2020-10-22T12:43:38Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99827#M1993</link>
      <description>&lt;P&gt;Yup , exactly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 12:45:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99827#M1993</guid>
      <dc:creator>Abhishek_Singh1</dc:creator>
      <dc:date>2020-10-22T12:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99929#M1994</link>
      <description>&lt;P&gt;does this Destination NAT work for other connections?&lt;/P&gt;&lt;P&gt;With two firewall instances I would expect that there is a chance of 50:50 that it will work as the internal LB is selecting the firewall&amp;nbsp; instance based on the IPs of the packet and as NAT is modifying one of these IPs, the loadbalancer could selecting a different instance for the return packet (as in your case).&lt;/P&gt;&lt;P&gt;But if so, I would expect more problems, not just for FTP -Passive.&lt;/P&gt;&lt;P&gt;Doing a Xlated Source NAT with&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;LocalGatewayInternal&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;should solve the problem.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Did you check the log to see that the Source IP is modified correctly ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A "dynamic_objects -l" on the instance should show you the IP attached to &lt;EM&gt;&lt;STRONG&gt;LocalGatewayInternal&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If the Source NAT is correct, is a UDR used&amp;nbsp; for&amp;nbsp; the subnet in which your destination&amp;nbsp;&lt;SPAN&gt;10.22.133.10 is deployed ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If so, please make sure, that the subnet of the internal Inferface of the VMSS is routed directly (next hop type Virtual network) and not forwared to the internal LB otherwise we would have the same problem&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 07:43:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99929#M1994</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-10-23T07:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99941#M1995</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8807"&gt;@Matthias_Haas&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find my response inline to your comments (&lt;EM&gt;in italic font&lt;/EM&gt;)--&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does this Destination NAT work for other connections? ---&amp;nbsp;&lt;EM&gt; we just have this single application traffic utilizing DNAT , no other used case so far.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;With two firewall instances I would expect that there is a chance of 50:50 that it will work as the internal LB is selecting the firewall&amp;nbsp; instance based on the IPs of the packet and as NAT is modifying one of these IPs, the loadbalancer could selecting a different instance for the return packet (as in your case).&lt;/P&gt;&lt;P&gt;But if so, I would expect more problems, not just for FTP -Passive.&lt;/P&gt;&lt;P&gt;Doing a Xlated Source NAT with&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;LocalGatewayInternal&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;should solve the problem.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Did you check the log to see that the Source IP is modified correctly ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A "dynamic_objects -l" on the instance should show you the IP attached to&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;LocalGatewayInternal&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;---&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;EM&gt;Yes, the source NAT is happening properly , have validated the translated Src to be fw&amp;nbsp; eth1 IP and Dst to be 10.22.133.10 using tcpdump &amp;amp; fw mon&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If the Source NAT is correct, is a UDR used&amp;nbsp; for&amp;nbsp; the subnet in which your destination&amp;nbsp;&lt;SPAN&gt;10.22.133.10 is deployed ? --&lt;EM&gt; Yes UDR is added on the FW internal interface eth1 subnet for destination&amp;nbsp;10.22.133.10 via&amp;nbsp;Virtual network (next hop)&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 11:28:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99941#M1995</guid>
      <dc:creator>Abhishek_Singh1</dc:creator>
      <dc:date>2020-10-23T11:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99943#M1996</link>
      <description>&lt;P&gt;also we enable one service on a random port 2222 , it works fine ... have observed issue with just Passive FTP connection ( 21 , data-port (2000 - 4000)) ...&lt;/P&gt;&lt;P&gt;Already allowed in access rule .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No issue observed for this FTP service in single instance (VMSS solution), or the earlier deployed cluster gateway &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 11:32:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99943#M1996</guid>
      <dc:creator>Abhishek_Singh1</dc:creator>
      <dc:date>2020-10-23T11:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99944#M1997</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;Abhishek,&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;lt;Yes UDR is added on the FW internal interface eth1 subnet for destination&amp;nbsp;10.22.133.10 via&amp;nbsp;Virtual network (next hop)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;I mean the UDR attached&amp;nbsp; to the subnet of the destination&amp;nbsp;10.22.133.10 (relevant for the return packet)?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Update: make sure, that the eth1 subnet is not forwarded to the internal LB&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 11:42:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99944#M1997</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-10-23T11:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99945#M1998</link>
      <description>&lt;P&gt;Ohk , thats UDR is pointing towards VMSS internal LB . ( Hence , we thought of adding Source Hide NAT to overcome asymmetric of return traffic).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically for all the subnets , as per design we have default route pointing towards VMSS internal LB so that checkpoint can inspect the traffic.&lt;/P&gt;&lt;P&gt;If in this case , I change the route for CP subnet directly vis Azure fabric , that would lead to CP missing the return traffic , isn't it ??&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 11:42:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99945#M1998</guid>
      <dc:creator>Abhishek_Singh1</dc:creator>
      <dc:date>2020-10-23T11:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99946#M1999</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;lt;If in this case , I change the route for CP subnet directly vis Azure fabric , that would lead to CP missing the return traffic , isn't it ??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;exactly (just for the internal/eth1 segment of the VMSS)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 11:48:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99946#M1999</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-10-23T11:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99980#M2000</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="49E78284-54B3-4602-89A3-A97AAB31A534.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8571i9CA1223C1105777D/image-size/large?v=v2&amp;amp;px=999" role="button" title="49E78284-54B3-4602-89A3-A97AAB31A534.jpeg" alt="49E78284-54B3-4602-89A3-A97AAB31A534.jpeg" /&gt;&lt;/span&gt;&lt;BR /&gt;that‘s the route you need to add&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 15:24:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/99980#M2000</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-10-23T15:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/100371#M2001</link>
      <description>&lt;P&gt;Yes , thats done as per the doc. Routing wise we are sorted , no split,asymmetric scenerio .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Finally with end-to-end packet captures , realized Checkpoint is specifically dropping&amp;nbsp;&lt;STRONG&gt;227 PASV response&lt;/STRONG&gt;&amp;nbsp;towards client whenever we enable SNAT .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Zdebug -&lt;/P&gt;&lt;P&gt;&lt;EM&gt;@;266774109;[cpu_2];[fw4_1];fw_log_drop_ex: Packet proto=6 x.x.x.x:21 -&amp;gt; y.y.y.y:17024 dropped by f&lt;STRONG&gt;w_post_vm_chain_handler Reason: Handler 'ftp_code' drop;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;kernel debug -&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;@;237812014;26Oct2020&amp;nbsp; 7:53:08.451195;[cpu_1];[fw4_2];fw_xlate_scan_ftp_cmd: 227 command;&lt;/P&gt;&lt;P&gt;@;237812014;26Oct2020&amp;nbsp; 7:53:08.451196;[cpu_1];[fw4_2];fw_xlate_anticipate_cookie: changing packet to &amp;lt;y.y.y.y, 9dd&amp;gt;;&lt;/P&gt;&lt;P&gt;@;237812014;26Oct2020&amp;nbsp; 7:53:08.451197;[cpu_1];[fw4_2];fw_xlate_update_packet: new field (len=16, delta=-1) is 'y,y,y,y,9,221';&lt;/P&gt;&lt;P&gt;@;237812014;26Oct2020&amp;nbsp; 7:53:08.451199;[cpu_1];[fw4_2];fw_xlate_update_length: Got -3 from fwseqvalid_reg_offset_deltas;&lt;/P&gt;&lt;P&gt;@;237812014;26Oct2020&amp;nbsp; 7:53:08.451200;[cpu_1];[fw4_2];fw_post_vm_chain_handler: handler function returned action DROP;&lt;/P&gt;&lt;P&gt;@;237812014;26Oct2020&amp;nbsp; 7:53:08.451202;[cpu_1];[fw4_2];fw_log_drop_ex: Packet proto=6 y.y.y.y:21 -&amp;gt; x.x.x.x:61627 dropped by &lt;STRONG&gt;fw_post_vm_chain_handler Reason: Handler 'ftp_code' drop&lt;/STRONG&gt;;&lt;/P&gt;&lt;P&gt;@;237812014;26Oct2020&amp;nbsp; 7:53:08.451204;[cpu_1];[fw4_2];After&amp;nbsp; POST VM: &amp;lt;dir 1, y.y.y.y:21 -&amp;gt; x.x.x.x:61627 IPP 6&amp;gt; (len=87) TCP flags=0x18 (PUSH-ACK), seq=3417305397, ack=951427193, data end=3417305444 ;&lt;/P&gt;&lt;P&gt;@;237812014;26Oct2020&amp;nbsp; 7:53:08.451205;[cpu_1];[fw4_2];POST VM Final action=DROP;&lt;/P&gt;&lt;P&gt;@;237812014;26Oct2020&amp;nbsp; 7:53:08.451205;[cpu_1];[fw4_2]; -----&amp;nbsp; Stateful POST VM outbound Completed -----&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; --- We have already opened a TAC case -&amp;nbsp;SR#6-0002342606 , but not getting proper attention . Can you please suggest and highlight this to appropriate Checkpoint resources . Thanks in Advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 11:35:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/100371#M2001</guid>
      <dc:creator>Abhishek_Singh1</dc:creator>
      <dc:date>2020-10-28T11:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/100372#M2002</link>
      <description>&lt;P&gt;Just to add on --- Have tried all the permutation &amp;amp; combination of Global Nat settings , Custom TCP service (with protocol as None) , sks available on internet search with this ftp_code drop , everything with no luck...&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 11:41:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/100372#M2002</guid>
      <dc:creator>Abhishek_Singh1</dc:creator>
      <dc:date>2020-10-28T11:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/100389#M2003</link>
      <description>&lt;P&gt;Have you tried:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112001" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112001&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 14:22:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/100389#M2003</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-28T14:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/100522#M2004</link>
      <description>&lt;P&gt;Yes , gone through that SK ... we aren't using FTP over TLS &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; . Plus , the client in our case is never receiving an response from Server . ( 227 PASV response from server is not relayed back to client , CP is dropping it)&lt;/P&gt;&lt;P&gt;Have already tried with custom TCP service , allowing port-21 , &amp;gt;1024 (with None as protocol) --- with no luck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way I can force Checkpoint to bypass the standard inspection for this traffic ??&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 09:28:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/100522#M2004</guid>
      <dc:creator>Abhishek_Singh1</dc:creator>
      <dc:date>2020-10-29T09:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Bi-directional NAT is not working post VMSS deployment</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/100709#M2005</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp; -- do you have any insights on this??&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 31 Oct 2020 11:57:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Bi-directional-NAT-is-not-working-post-VMSS-deployment/m-p/100709#M2005</guid>
      <dc:creator>Abhishek_Singh1</dc:creator>
      <dc:date>2020-10-31T11:57:47Z</dc:date>
    </item>
  </channel>
</rss>

