<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT problem in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65542#M12181</link>
    <description>So you changed the IP in the VS object, did you also push the policy? Both VS and VSX cluster would be best to push, normally only the VS policy needs to be pushed, but it wont hurt to also push the Cluster itself as well.</description>
    <pubDate>Tue, 22 Oct 2019 08:42:12 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2019-10-22T08:42:12Z</dc:date>
    <item>
      <title>NAT problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65527#M12178</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A week or so ago we changed an ip address on one of our interfaces from 10.157.1.10 to 10.184.0.2 we also changed the NAT rules that was configured to the old ip address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But now still the firewall sends packets with the old ip of 10.157.1.10 and 12 even when those addreses are unconfigured.&lt;/P&gt;&lt;P&gt;Running R80.20 with HFA 103&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;//Johan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 07:45:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65527#M12178</guid>
      <dc:creator>Johan_Rudberg</dc:creator>
      <dc:date>2019-10-22T07:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65538#M12179</link>
      <description>Is this part of a cluster? Did you change the IP's in clish and in SmartConsole?&lt;BR /&gt;</description>
      <pubDate>Tue, 22 Oct 2019 08:29:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65538#M12179</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-10-22T08:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65541#M12180</link>
      <description>&lt;P&gt;Yes its a VSX cluster with two physical GWs and two VSes, the change was made in SmartConsole.&lt;/P&gt;&lt;P&gt;//Johan&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 08:31:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65541#M12180</guid>
      <dc:creator>Johan_Rudberg</dc:creator>
      <dc:date>2019-10-22T08:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65542#M12181</link>
      <description>So you changed the IP in the VS object, did you also push the policy? Both VS and VSX cluster would be best to push, normally only the VS policy needs to be pushed, but it wont hurt to also push the Cluster itself as well.</description>
      <pubDate>Tue, 22 Oct 2019 08:42:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65542#M12181</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-10-22T08:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65543#M12182</link>
      <description>&lt;P&gt;Yes we have pushed VS policy several times and the cluster policy once now, but still the old ip address is used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;//Johan&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 09:02:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65543#M12182</guid>
      <dc:creator>Johan_Rudberg</dc:creator>
      <dc:date>2019-10-22T09:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65545#M12183</link>
      <description>&lt;P&gt;Any chance you have proxy arp in place?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 09:20:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65545#M12183</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-10-22T09:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65552#M12184</link>
      <description>&lt;P&gt;Yes the automatic default Proxy ARP is enabled and the Merge Manual setting too, however in the local.arp file there is only one entry with the new ip address in it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;//Johan&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 10:14:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65552#M12184</guid>
      <dc:creator>Johan_Rudberg</dc:creator>
      <dc:date>2019-10-22T10:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65570#M12185</link>
      <description>&lt;P&gt;Please provide a log screenshot of accepted traffic still being NATted to the old address, the log card will show the NAT rules involved.&amp;nbsp; Keep in mind that after changing a NAT address only new connections will start using it, old connections will continue using the old NAT address until they end.&amp;nbsp; Are sure you are launching NEW connections for testing and not still riding on old ones?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 13:42:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65570#M12185</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-10-22T13:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65574#M12186</link>
      <description>Thank you we look into that!&lt;BR /&gt;&lt;BR /&gt;//Johan</description>
      <pubDate>Tue, 22 Oct 2019 14:24:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-problem/m-p/65574#M12186</guid>
      <dc:creator>Johan_Rudberg</dc:creator>
      <dc:date>2019-10-22T14:24:45Z</dc:date>
    </item>
  </channel>
</rss>

