<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Outbound NAT Azure HA Cluster in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183455#M2353</link>
    <description>&lt;P&gt;Thanks for the response Edan,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;just on this" comment Keep in mind, it will not use the VIP but the public address of the active gateway itself." if my gateways failover then NAT IP will change is that correct.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there any NAT option to hide for example all " source 10.0.0.0/8" behind VIP of the clusters, so egress IP will not change.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also I want to create Manual NAT as below&amp;nbsp;not&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;automatic.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Original&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Source: 10.0.0.0/8&amp;nbsp; Original Destination: internet&amp;nbsp; Org srv:any Translated Source : ????&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;what will be the translated&amp;nbsp;source, VIP public, VIP private Gateway IP&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;many thanks in advance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jun 2023 12:42:23 GMT</pubDate>
    <dc:creator>Salman2020</dc:creator>
    <dc:date>2023-06-07T12:42:23Z</dc:date>
    <item>
      <title>Outbound NAT Azure HA Cluster</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/85007#M2349</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I’ve got a Check Point R80.30 HA cluster deployed in Azure following the latest sk.&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110194&amp;amp;partition=Basic&amp;amp;product=CloudGuard" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110194&amp;amp;partition=Basic&amp;amp;product=CloudGuard&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;As a next step I am looking to leverage the Check Point cluster to be the Internet gateway for outbound Internet traffic and perform outbound NAT to the subnets behind it.&lt;/P&gt;&lt;P&gt;I'm not looking to do automatic NAT. &amp;nbsp;So for my NAT rules...just for a sanity check - I’m NATing my traffic so that it changes the translated source to the private Cluster VIP address?&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 03:10:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/85007#M2349</guid>
      <dc:creator>dd84</dc:creator>
      <dc:date>2020-05-13T03:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound NAT Azure HA Cluster</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/85313#M2350</link>
      <description>That sounds correct.&lt;BR /&gt;The final NAT to a public address happens within Azure.</description>
      <pubDate>Thu, 14 May 2020 17:39:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/85313#M2350</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-14T17:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound NAT Azure HA Cluster</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/182949#M2351</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have the same question to NAT outbound Internet traffic behind checkpoint cloudguard cluster, don't find any clear documentation. Can someone please help&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I want to NAT all internal client behind cluster IP for outbound internet access.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2023 15:58:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/182949#M2351</guid>
      <dc:creator>Salman2020</dc:creator>
      <dc:date>2023-06-01T15:58:17Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound NAT Azure HA Cluster</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183015#M2352</link>
      <description>&lt;P&gt;Hi Salman2020&lt;BR /&gt;You can use the "hide behind gateway" feature on any host or network you choose.&lt;/P&gt;
&lt;P&gt;Keep in mind, it will not use the VIP but the public address of the active gateway itself.&lt;/P&gt;
&lt;P&gt;You can find this in the admin guide as well:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-06-02 07_34_07-Workflow for Setting Up a High Availability Cluster in Azure and 2 more pages - .png" style="width: 799px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21236iBFAF33C369A5D31F/image-size/large?v=v2&amp;amp;px=999" role="button" title="2023-06-02 07_34_07-Workflow for Setting Up a High Availability Cluster in Azure and 2 more pages - .png" alt="2023-06-02 07_34_07-Workflow for Setting Up a High Availability Cluster in Azure and 2 more pages - .png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 04:34:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183015#M2352</guid>
      <dc:creator>Edan_Leventhal</dc:creator>
      <dc:date>2023-06-02T04:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound NAT Azure HA Cluster</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183455#M2353</link>
      <description>&lt;P&gt;Thanks for the response Edan,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;just on this" comment Keep in mind, it will not use the VIP but the public address of the active gateway itself." if my gateways failover then NAT IP will change is that correct.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there any NAT option to hide for example all " source 10.0.0.0/8" behind VIP of the clusters, so egress IP will not change.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also I want to create Manual NAT as below&amp;nbsp;not&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;automatic.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Original&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Source: 10.0.0.0/8&amp;nbsp; Original Destination: internet&amp;nbsp; Org srv:any Translated Source : ????&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;what will be the translated&amp;nbsp;source, VIP public, VIP private Gateway IP&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;many thanks in advance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 12:42:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183455#M2353</guid>
      <dc:creator>Salman2020</dc:creator>
      <dc:date>2023-06-07T12:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound NAT Azure HA Cluster</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183512#M2354</link>
      <description>&lt;P&gt;If you want a no NAT rule, then the "translated source/destination/service" will be "Original" and should be listed at the top of the NAT rulebase.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 16:06:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183512#M2354</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-07T16:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound NAT Azure HA Cluster</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183552#M2355</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I want to create Manual NAT rule.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Example: &lt;/SPAN&gt;&lt;SPAN&gt;Original&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Source: 10.0.0.0/8&amp;nbsp; Original Destination: internet&amp;nbsp; &amp;nbsp;Translated Source : ????&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;what should be the translated&amp;nbsp;source ?&amp;nbsp; VIP public of cluster , VIP private Gateway IP or public IP of active Gateway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Our Cloudguard HA pair running as Active/Standby.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 20:14:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183552#M2355</guid>
      <dc:creator>Salman2020</dc:creator>
      <dc:date>2023-06-07T20:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound NAT Azure HA Cluster</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183554#M2356</link>
      <description>&lt;P&gt;For Azure to do the final NAT to a public address, you would need to use a private IP.&lt;BR /&gt;On this case, not sure if you use the private VIP or just the IP of the gateway.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2023 21:02:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183554#M2356</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-07T21:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound NAT Azure HA Cluster</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183580#M2357</link>
      <description>&lt;P&gt;Hi Salman,&lt;/P&gt;
&lt;P&gt;Technically you can use the hide behind gateway feature to hide behind the private IP of the VIP and it will work.&lt;/P&gt;
&lt;DIV id="tinyMceEditor_9414b89a7bcdbEdan_Leventhal_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;Do note, as this configuration is not mentioned in the admin guide, this is not a supported configuration by support.&lt;/P&gt;
&lt;P&gt;Additionally, I'm not sure what is your goal with this, but if it's do avoid downtime, I would like to remind you that due to Azure limitations failover in Azure involves up to 15 seconds of downtime, and up to 2 minutes if VPN is used.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jun 2023 03:23:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183580#M2357</guid>
      <dc:creator>Edan_Leventhal</dc:creator>
      <dc:date>2023-06-08T03:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound NAT Azure HA Cluster</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183801#M2358</link>
      <description>&lt;P&gt;Thanks Edan,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;From your comment : Do note, as this configuration is not mentioned in the admin guide, this is not a supported configuration by support.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;what is the supported config ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 11:36:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183801#M2358</guid>
      <dc:creator>Salman2020</dc:creator>
      <dc:date>2023-06-12T11:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Outbound NAT Azure HA Cluster</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183815#M2359</link>
      <description>&lt;P&gt;Hi Salman,&lt;/P&gt;
&lt;P&gt;The supported config is what was mentioned earlier from the admin guide with "hide behind gateway"&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2023 13:49:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Outbound-NAT-Azure-HA-Cluster/m-p/183815#M2359</guid>
      <dc:creator>Edan_Leventhal</dc:creator>
      <dc:date>2023-06-12T13:49:54Z</dc:date>
    </item>
  </channel>
</rss>

