<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hide NAT issue in a lab environment in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-issue-in-a-lab-environment/m-p/88455#M11092</link>
    <description>&lt;P&gt;As per 0.PNG, rule 2 is doing Hide NAT.&amp;nbsp; Can you share NAT rule base?&lt;/P&gt;</description>
    <pubDate>Sun, 14 Jun 2020 03:11:57 GMT</pubDate>
    <dc:creator>pal</dc:creator>
    <dc:date>2020-06-14T03:11:57Z</dc:date>
    <item>
      <title>Hide NAT issue in a lab environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-issue-in-a-lab-environment/m-p/85452#M11090</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I'm currently using a SA R80.10 cloud-based lab&amp;nbsp;environment.&lt;BR /&gt;&lt;BR /&gt;I have the following networks:&lt;/P&gt;&lt;DIV class="data-container"&gt;&lt;DIV class="list"&gt;&lt;DIV class="list-item"&gt;10.159.253.0/24 - VPN&amp;nbsp;&lt;BR /&gt;10.159.11.0/24 - Server LAN (one IP is being used by Windows Server which acts as a DC)&lt;BR /&gt;10.159.254.0/24 - FW External&amp;nbsp;(eth0)&lt;BR /&gt;10.159.0.0/24 - FW Internal (eth1)&lt;BR /&gt;10.159.1.0/24 - User LAN (one IP is being used by Windows Server which acts as a client).&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="data-container"&gt;&lt;DIV class="list"&gt;&lt;DIV class="list-item"&gt;&lt;BR /&gt;1) I have configured a rule to allow the client to send DNS requests to the DC + Hide NAT for both networks.&lt;BR /&gt;2) Since both networks are internal networks (Server LAN + User LAN), NAT should not take place at the first&amp;nbsp;phase (when I execute nslookup and the client sends a packet from User-LAN to the DC which is part of Server Lan).&lt;BR /&gt;3) Hide NAT should take place only when the DC sends a DNS request to the FW, and the FW realise that he needs to forward it using his external interface. ("o to O inspection point - after routing decision took place").&lt;BR /&gt;&lt;BR /&gt;For now, I have created a manual NAT rule that is located on top to bypass this.&lt;BR /&gt;(original source: Client, Original destination DC, translated source: original, translated destination: original)&lt;BR /&gt;Without this rule, anti-spoofing drops the traffic (because Xlate Source IP is 10.178.254.254 which is FW EXT eth0)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;BR /&gt;Assistance would be greatly appreciated!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I've tried several things... I will mention few of them:&lt;BR /&gt;Under network management &amp;gt; eth1 the network address is 10.178.0.254/24&amp;nbsp;&lt;BR /&gt;I clicked modify &amp;gt; override &amp;gt; specific and selected a group that contains server and user lan. set as detected.&lt;BR /&gt;eth0 &amp;gt; set as detect.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;The last thing I did is to go to Network topology and set eth1 to /24 and add the network group that contains server+user lan &amp;amp; change eth0 s.mask to /32. It didn't work either....&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 May 2020 23:17:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-issue-in-a-lab-environment/m-p/85452#M11090</guid>
      <dc:creator>efraim</dc:creator>
      <dc:date>2020-05-16T23:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT issue in a lab environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-issue-in-a-lab-environment/m-p/88443#M11091</link>
      <description>&lt;P&gt;Nobody?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jun 2020 20:31:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-issue-in-a-lab-environment/m-p/88443#M11091</guid>
      <dc:creator>efraim</dc:creator>
      <dc:date>2020-06-13T20:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT issue in a lab environment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-issue-in-a-lab-environment/m-p/88455#M11092</link>
      <description>&lt;P&gt;As per 0.PNG, rule 2 is doing Hide NAT.&amp;nbsp; Can you share NAT rule base?&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jun 2020 03:11:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-issue-in-a-lab-environment/m-p/88455#M11092</guid>
      <dc:creator>pal</dc:creator>
      <dc:date>2020-06-14T03:11:57Z</dc:date>
    </item>
  </channel>
</rss>

