<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The NAT issue on CP firewall deployed in the Azure in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/The-NAT-issue-on-CP-firewall-deployed-in-the-Azure/m-p/55983#M2938</link>
    <description>&lt;P&gt;We have built tunnel between the CP firewall (FW1) in Azure and CP firewall(FW2) in On-Primese.&lt;/P&gt;&lt;P&gt;The FW1 is a cluster and has two gateways in it. IP of gateway 1 is 10.10.10.4, IP of gateway 2 is 10.10.10.5 and IP of Cluster is 10.10.10.6. Gateway 1 is active&lt;/P&gt;&lt;P&gt;The tunnel initiation traffic/Phase 1 traffic is sent by the FW2 from port 500 to port 500 of FW 1.&lt;/P&gt;&lt;P&gt;We have done packet capture on the gateway 1 of FW1 and found that the the FW1 is receiving the traffic on cluster IP sent by the FW2, both source and destination ports are 500.&lt;/P&gt;&lt;P&gt;The gateway1 of the FW1 is replying to the FW2 from port 500 to port 500 of FW2&lt;/P&gt;&lt;P&gt;In the next packet while the gateway 1 IP is getting translated to the cluster IP i.e, from 10.10.10.4 to 10.10.10.6 the source port is also getting translated from port 500 to random port. Below are the logs collected from gateway 1&lt;/P&gt;&lt;P&gt;[vs_0][fw_0] eth0:o[180]: X.X.X.X -&amp;gt; 10.10.10.6 (UDP) len=180 id=20396&lt;BR /&gt;UDP: 500 -&amp;gt; 500&lt;BR /&gt;[vs_0][fw_0] eth0:o[180]: 10.10.10.4 -&amp;gt; X.X.X.X (UDP) len=180 id=10087&lt;BR /&gt;UDP: 500 -&amp;gt; 500&lt;BR /&gt;[vs_0][fw_0] eth0:O[180]: 10.10.10.6 -&amp;gt; X.X.X.X (UDP) len=180 id=10087&lt;BR /&gt;UDP: 12410 -&amp;gt; 500&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due to this the phase 1 of the tunnel is not getting established and the tunnel is not forming. Kindly provide a solution to this.&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jun 2019 16:09:48 GMT</pubDate>
    <dc:creator>Krishna</dc:creator>
    <dc:date>2019-06-17T16:09:48Z</dc:date>
    <item>
      <title>The NAT issue on CP firewall deployed in the Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/The-NAT-issue-on-CP-firewall-deployed-in-the-Azure/m-p/55983#M2938</link>
      <description>&lt;P&gt;We have built tunnel between the CP firewall (FW1) in Azure and CP firewall(FW2) in On-Primese.&lt;/P&gt;&lt;P&gt;The FW1 is a cluster and has two gateways in it. IP of gateway 1 is 10.10.10.4, IP of gateway 2 is 10.10.10.5 and IP of Cluster is 10.10.10.6. Gateway 1 is active&lt;/P&gt;&lt;P&gt;The tunnel initiation traffic/Phase 1 traffic is sent by the FW2 from port 500 to port 500 of FW 1.&lt;/P&gt;&lt;P&gt;We have done packet capture on the gateway 1 of FW1 and found that the the FW1 is receiving the traffic on cluster IP sent by the FW2, both source and destination ports are 500.&lt;/P&gt;&lt;P&gt;The gateway1 of the FW1 is replying to the FW2 from port 500 to port 500 of FW2&lt;/P&gt;&lt;P&gt;In the next packet while the gateway 1 IP is getting translated to the cluster IP i.e, from 10.10.10.4 to 10.10.10.6 the source port is also getting translated from port 500 to random port. Below are the logs collected from gateway 1&lt;/P&gt;&lt;P&gt;[vs_0][fw_0] eth0:o[180]: X.X.X.X -&amp;gt; 10.10.10.6 (UDP) len=180 id=20396&lt;BR /&gt;UDP: 500 -&amp;gt; 500&lt;BR /&gt;[vs_0][fw_0] eth0:o[180]: 10.10.10.4 -&amp;gt; X.X.X.X (UDP) len=180 id=10087&lt;BR /&gt;UDP: 500 -&amp;gt; 500&lt;BR /&gt;[vs_0][fw_0] eth0:O[180]: 10.10.10.6 -&amp;gt; X.X.X.X (UDP) len=180 id=10087&lt;BR /&gt;UDP: 12410 -&amp;gt; 500&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Due to this the phase 1 of the tunnel is not getting established and the tunnel is not forming. Kindly provide a solution to this.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2019 16:09:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/The-NAT-issue-on-CP-firewall-deployed-in-the-Azure/m-p/55983#M2938</guid>
      <dc:creator>Krishna</dc:creator>
      <dc:date>2019-06-17T16:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: The NAT issue on CP firewall deployed in the Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/The-NAT-issue-on-CP-firewall-deployed-in-the-Azure/m-p/56013#M2939</link>
      <description>Curious what evidence you have to suggest this change of port is causing the issue?&lt;BR /&gt;What do logs or VPN debugs say?</description>
      <pubDate>Tue, 18 Jun 2019 04:39:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/The-NAT-issue-on-CP-firewall-deployed-in-the-Azure/m-p/56013#M2939</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-18T04:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: The NAT issue on CP firewall deployed in the Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/The-NAT-issue-on-CP-firewall-deployed-in-the-Azure/m-p/56017#M2940</link>
      <description>The Phase 1 packets for the tunnel is exchanged between ports 500 or 4500 on both the ends, as the port is getting changed the other than these two , other end firewall will ignore/ drop the phase 1 traffic.</description>
      <pubDate>Tue, 18 Jun 2019 05:40:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/The-NAT-issue-on-CP-firewall-deployed-in-the-Azure/m-p/56017#M2940</guid>
      <dc:creator>Krishna</dc:creator>
      <dc:date>2019-06-18T05:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: The NAT issue on CP firewall deployed in the Azure</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/The-NAT-issue-on-CP-firewall-deployed-in-the-Azure/m-p/58244#M2941</link>
      <description>The issue got resolved after no NAT rule is created for the cluster IP. Below is the no NAT rule added.&lt;BR /&gt;&lt;BR /&gt;Original Source: Cluster IP.&lt;BR /&gt;Original Destination : Any&lt;BR /&gt;Original port: IKE&lt;BR /&gt;&lt;BR /&gt;Translated Source: Cluster IP&lt;BR /&gt;Translated destination : Original&lt;BR /&gt;Translated Port : Original&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Jul 2019 09:56:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/The-NAT-issue-on-CP-firewall-deployed-in-the-Azure/m-p/58244#M2941</guid>
      <dc:creator>Krishna</dc:creator>
      <dc:date>2019-07-15T09:56:19Z</dc:date>
    </item>
  </channel>
</rss>

