<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: STATIC NAT in Azure Checkpoint in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129992#M2555</link>
    <description>&lt;P&gt;A question regarding&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/58831"&gt;@yunier88&lt;/a&gt; &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1792"&gt;@Nir_Shamir&lt;/a&gt;&amp;nbsp;, initial question; After adding an in Azure Portal Secondary Static Private IP with a Public IP, should the Network Interface panel in the WebUI browser; should we see an alias with its new Private IP and Public IP? Or do we need to manually add in the WebUI this Private and Public IPs?&lt;/P&gt;</description>
    <pubDate>Wed, 22 Sep 2021 19:34:21 GMT</pubDate>
    <dc:creator>AndyS</dc:creator>
    <dc:date>2021-09-22T19:34:21Z</dc:date>
    <item>
      <title>STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/75730#M2535</link>
      <description>&lt;P&gt;How to configure Static NAT (Bi-directional)&amp;nbsp; and Outbound NAT (Source NAT) in Azure Checkpoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have 3 VMs and want to send outbound traffic towards internet each with unique public IP. how can we configure such type of NAT in Azure checkpoint point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Upen&lt;/P&gt;</description>
      <pubDate>Wed, 19 Feb 2020 12:56:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/75730#M2535</guid>
      <dc:creator>upendras</dc:creator>
      <dc:date>2020-02-19T12:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/75802#M2536</link>
      <description>&lt;P&gt;Hi Upen,&lt;/P&gt;&lt;P&gt;are&amp;nbsp; you using a Single Gateway ?&lt;/P&gt;&lt;P&gt;In this case you could use additional public/private IPs on the external Interface (eth0) of the FW:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="interface.png" style="width: 704px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4525iD05F7BD31E8CE940/image-dimensions/704x271?v=v2" width="704" height="271" role="button" title="interface.png" alt="interface.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and do the Source NAT for each vm on the FW&amp;nbsp; (to the Private IP, Azure in return is then NATing to the Public IP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4526i47DF07E153649F30/image-size/large?v=v2&amp;amp;px=999" role="button" title="NAT.png" alt="NAT.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;At least a outbound NAT is possible in this case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Matthias&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 04:45:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/75802#M2536</guid>
      <dc:creator>Matthias_Haas</dc:creator>
      <dc:date>2020-04-15T04:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/75834#M2537</link>
      <description>&lt;P&gt;I have cluster in Azure.. and want to outbound NAT like VM private IP 10.1.1.1 go to Internet, it will be NATTed with 1.1.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please help me suggest how can I achieve this...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Upen&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2020 07:10:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/75834#M2537</guid>
      <dc:creator>upendras</dc:creator>
      <dc:date>2020-02-20T07:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/85097#M2538</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8807"&gt;@Matthias_Haas&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That will not work for an HA cluster, since that from Azure side you'll not be able to assign the same Public IP object to two different network interfaces.&lt;/P&gt;&lt;P&gt;How can we bypass this?&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 16:54:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/85097#M2538</guid>
      <dc:creator>bmomartins</dc:creator>
      <dc:date>2020-05-13T16:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/126912#M2539</link>
      <description>&lt;P&gt;Is there any resolution to this?&amp;nbsp; How do we fix this on an HA Cluster ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 11:39:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/126912#M2539</guid>
      <dc:creator>Nick_Mandafouni</dc:creator>
      <dc:date>2021-08-13T11:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128262#M2540</link>
      <description>&lt;P&gt;Hello there,&lt;BR /&gt;In my case I need to know how to add a new public IP in my FW to be used by my prod Vnet in outbond. Currently all my VNETS (backend) when they go to the internet use the same public IP. But in my environment I need the Prod VNET to use a different public IP than the rest of the other Vnets. Somebody could help me? Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 19:15:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128262#M2540</guid>
      <dc:creator>yunier88</dc:creator>
      <dc:date>2021-08-27T19:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128294#M2541</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I know that if you remove the Public IPs from the instances themselves (not the VIP) then the GWs will go out via the Frontend LB and then you can create an Outbound NAT rules on the Frontend LB with a different PIP which is allocated on the Frontend LB&lt;/P&gt;</description>
      <pubDate>Sun, 29 Aug 2021 07:01:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128294#M2541</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2021-08-29T07:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128589#M2542</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;Do you have an example of the necessary rules to create in the Firewall and in the Load Balancer?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 17:34:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128589#M2542</guid>
      <dc:creator>yunier88</dc:creator>
      <dc:date>2021-09-01T17:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128637#M2543</link>
      <description>&lt;P&gt;usually the frontend-lb is created with an example rule you can copy. the Firewall NAT rules can be seen our admin guide:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_Azure/Content/Topics-Azure-HA/Workflow-for-Setting-Up-a-High-Availability-Cluster-in-Azure.htm?tocpath=Workflow%20for%20Setting%20Up%20a%20High%20Availability%20Cluster%20in%20Azure%7C_____0#Step_7__Set_Up_the_External_Load_Balancer_in_Azure" target="_blank"&gt;https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_IaaS_HighAvailability_for_Azure/Content/Topics-Azure-HA/Workflow-for-Setting-Up-a-High-Availability-Cluster-in-Azure.htm?tocpath=Workflow%20for%20Setting%20Up%20a%20High%20Availability%20Cluster%20in%20Azure%7C_____0#Step_7__Set_Up_the_External_Load_Balancer_in_Azure&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 12:03:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128637#M2543</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2021-09-02T12:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128654#M2544</link>
      <description>&lt;P&gt;Just to be sure, this information that you share with me is for outbond traffic. Since in my case I already managed to carry out inbound traffic with an LB. Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 15:47:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128654#M2544</guid>
      <dc:creator>yunier88</dc:creator>
      <dc:date>2021-09-02T15:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128740#M2545</link>
      <description>&lt;P&gt;no, that's for Inbound traffic.&lt;/P&gt;
&lt;P&gt;For outbound you need to create outbound NAT rules on the Fronend-LB.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Sep 2021 07:58:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128740#M2545</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2021-09-05T07:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128963#M2546</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;Do you know where I can find some configuration example?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 15:31:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/128963#M2546</guid>
      <dc:creator>yunier88</dc:creator>
      <dc:date>2021-09-08T15:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129005#M2547</link>
      <description>&lt;P&gt;I don't know if there are examples some where but the procedure is like this:&lt;/P&gt;
&lt;P&gt;1) remove the PIPs from the Cluster members.&lt;/P&gt;
&lt;P&gt;2) add a NAT rule which hides you specific traffic behind the cluster members external IP (Dynamic object named 'LocalGatewayExternal'&lt;/P&gt;
&lt;P&gt;3) create an Outbound rule on the Frontend-LB behind a specific Frontend PIP for your specific traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;all the traffic that equals to that rule will be hidden behind the Frontend-LB PIP and not the Cluster VIP.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Sep 2021 08:09:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129005#M2547</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2021-09-09T08:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129041#M2548</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;In my case it is a single gateway. The procediment will be the same?&lt;/P&gt;&lt;P&gt;On the other hand when you say: 1) remove the PIPs from the Cluster members.&lt;BR /&gt;In my case I cannot delete my only public IP from the Gateway, it is used for S2S and P2S VPN connection. Please can you explain in more detail?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 09 Sep 2021 14:15:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129041#M2548</guid>
      <dc:creator>yunier88</dc:creator>
      <dc:date>2021-09-09T14:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129054#M2549</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;In this solution you provide. Is it necessary to change something in the routing of the FW? So that the main public IP (created by default) remains the IP for S2S and P2S VPN and Hide nat?&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Thu, 09 Sep 2021 15:17:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129054#M2549</guid>
      <dc:creator>yunier88</dc:creator>
      <dc:date>2021-09-09T15:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129195#M2550</link>
      <description>&lt;P&gt;On a single gateway it's much more easier.&lt;/P&gt;
&lt;P&gt;you can add a secondary private IP on the external interface of the Gateway (usually eth0) and attach to it a new PIP.&lt;/P&gt;
&lt;P&gt;then in the rule base you do Source-NAT on your specific server and hide it behind the new Private IP you added.&lt;/P&gt;
&lt;P&gt;From there it will be hidden behind the new PIP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Sep 2021 06:56:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129195#M2550</guid>
      <dc:creator>Nir_Shamir</dc:creator>
      <dc:date>2021-09-12T06:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129227#M2551</link>
      <description>&lt;P&gt;For VPN to work in this situation, you'll probably have to adjust the Link Selection setting in the relevant gateway object to use the public IP.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 02:19:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129227#M2551</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-13T02:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129437#M2552</link>
      <description>&lt;P&gt;Thanks, I'll try that solution&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 19:40:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129437#M2552</guid>
      <dc:creator>yunier88</dc:creator>
      <dc:date>2021-09-14T19:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129438#M2553</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Here I share a screenshot of my configuration in Link selection settings. Do you think the configuration is correct for the main public IP (created by default) remains the IP for S2S and P2S VPN and Hide nat? The ip you see in the screenshot 52xxxxxx is my main public IP.&lt;BR /&gt;Do you think that with this configuration there is no problem when I create other public IPs in the eth0 interface of my FW?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 19:41:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129438#M2553</guid>
      <dc:creator>yunier88</dc:creator>
      <dc:date>2021-09-14T19:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: STATIC NAT in Azure Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129440#M2554</link>
      <description>&lt;P&gt;Yes this is how you’d configure it.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 20:50:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/STATIC-NAT-in-Azure-Checkpoint/m-p/129440#M2554</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-14T20:50:33Z</dc:date>
    </item>
  </channel>
</rss>

