<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC PUBLIC IP BEHAIND NAT in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260863#M5570</link>
    <description>&lt;P&gt;Scroll further right in the SmartView Monitor, is NAT-T active for that tunnel?&amp;nbsp; If not make sure support for it is enabled on both sides.&amp;nbsp; Also you'll need to implement Phoneboy's suggestion concerning Link Selection.&lt;/P&gt;</description>
    <pubDate>Sat, 25 Oct 2025 15:02:32 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2025-10-25T15:02:32Z</dc:date>
    <item>
      <title>IPSEC PUBLIC IP BEHAIND NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260779#M5565</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We created the the ipsec with in our&amp;nbsp; lab firewall checkpoint and FortiGate , my checkpoint topology having private ip&amp;nbsp;&lt;/P&gt;&lt;P&gt;the nat happen on redhat openstack portal tunnel is up but i cat able to reach the destination side&lt;/P&gt;&lt;P&gt;is there any thing else need to check&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31805iD2A5DD0F4E5BC6E1/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp.png" alt="cp.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Siddu&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 07:18:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260779#M5565</guid>
      <dc:creator>siddu099</dc:creator>
      <dc:date>2025-10-24T07:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC PUBLIC IP BEHAIND NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260801#M5566</link>
      <description>&lt;P&gt;Hey Siddu,&lt;/P&gt;
&lt;P&gt;What have you done so far as far as troubleshooting? Any packet captures, debugs, any logs you can share? Just telling us something is not accessible does not tell us anything, sorry &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 12:11:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260801#M5566</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-24T12:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC PUBLIC IP BEHAIND NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260803#M5567</link>
      <description>&lt;P&gt;For starters, run this from expert mode:&lt;/P&gt;
&lt;P&gt;fw ctl zdebug + drop | grep x.x.x.x&lt;/P&gt;
&lt;P&gt;Just replace x.x.x.x with dst IP&lt;/P&gt;
&lt;P&gt;ctrl c to stop and observe if any messages/logs&lt;/P&gt;
&lt;P&gt;On FGT side:&lt;/P&gt;
&lt;P&gt;di de di&lt;/P&gt;
&lt;P&gt;di de app ike -1&lt;/P&gt;
&lt;P&gt;di di en&lt;/P&gt;
&lt;P&gt;observe debug messages&lt;/P&gt;
&lt;P&gt;q to stop and di de di again&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 12:40:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260803#M5567</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-24T12:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC PUBLIC IP BEHAIND NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260827#M5568</link>
      <description>&lt;P&gt;You need to configure Link Selection in the gateway/cluster object.&lt;BR /&gt;R82 offers the Enhanced Link Selection option, but this is how you can configure it in any version:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31815iFFC273276424369E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 21:05:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260827#M5568</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-10-24T21:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC PUBLIC IP BEHAIND NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260861#M5569</link>
      <description>&lt;P&gt;Good point! I assumed that was set already, but definitely worth confirming.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Oct 2025 14:53:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260861#M5569</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-25T14:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC PUBLIC IP BEHAIND NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260863#M5570</link>
      <description>&lt;P&gt;Scroll further right in the SmartView Monitor, is NAT-T active for that tunnel?&amp;nbsp; If not make sure support for it is enabled on both sides.&amp;nbsp; Also you'll need to implement Phoneboy's suggestion concerning Link Selection.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Oct 2025 15:02:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260863#M5570</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-10-25T15:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC PUBLIC IP BEHAIND NAT</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260870#M5571</link>
      <description>&lt;P&gt;I believe NAT-T is by default enabled on both CP and FGT.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Oct 2025 16:13:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/IPSEC-PUBLIC-IP-BEHAIND-NAT/m-p/260870#M5571</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-25T16:13:44Z</dc:date>
    </item>
  </channel>
</rss>

