<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Nat rule over tunnel/community in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/50494#M12972</link>
    <description>Is the Public IP included in your encryption domain for the remote site?</description>
    <pubDate>Wed, 10 Apr 2019 21:00:40 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-04-10T21:00:40Z</dc:date>
    <item>
      <title>Nat rule over tunnel/community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/50488#M12971</link>
      <description>&lt;P&gt;Hi.&amp;nbsp; Im trying to redirect traffic going out a gateway.&amp;nbsp; I want to change the traffic flow from:&lt;/P&gt;&lt;P&gt;host_a (port 443) -&amp;gt; checkpoint_gateway -&amp;gt; internet -&amp;gt; public ip on host_b&lt;/P&gt;&lt;P&gt;to:&lt;/P&gt;&lt;P&gt;host_a (port 443) -&amp;gt; checkpoint_gateway -&amp;gt; nat from public ip on host_b to private ip on host_b -&amp;gt; s2s ipsec tunnel -&amp;gt; private ip on host_b&lt;/P&gt;&lt;P&gt;The tunnel works fine for normal traffic flow over the tunnel and all the security domains are defined properly.&amp;nbsp; There are rules in the policy that the traffic should hit to go over the tunnel.&amp;nbsp; When I try to create a nat rule to change the public ip to the private ip of host_b the traffic is allowed and I see the translation but It doesnt get encrypted.&amp;nbsp; Its also skipping my tunnel rule and hitting my default outbound rule at the bottom.&amp;nbsp; What am I missing in my nat rule to get this traffic flow working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 20:04:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/50488#M12971</guid>
      <dc:creator>PIAndre</dc:creator>
      <dc:date>2019-04-10T20:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: Nat rule over tunnel/community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/50494#M12972</link>
      <description>Is the Public IP included in your encryption domain for the remote site?</description>
      <pubDate>Wed, 10 Apr 2019 21:00:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/50494#M12972</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-10T21:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Nat rule over tunnel/community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/50497#M12973</link>
      <description>You need to make sure that the Public ip host_b and translated IP for Host_b is part of the remote VPN domain.&lt;BR /&gt;NAT finds place as one of the last parts in the outbound chain and this traffic should already be seen as traffic to send to the other side of the tunnel before that NAT takes place.</description>
      <pubDate>Wed, 10 Apr 2019 21:52:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/50497#M12973</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-04-10T21:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: Nat rule over tunnel/community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/50640#M12974</link>
      <description>&lt;P&gt;I just tested with one host behind the gateway.&amp;nbsp; So the nat rule looks like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;original source - test_host&lt;/P&gt;&lt;P&gt;original destination - public ip on host_b&lt;/P&gt;&lt;P&gt;original services - any&lt;/P&gt;&lt;P&gt;translated source - original&lt;/P&gt;&lt;P&gt;translated destination - private ip on host_b&lt;/P&gt;&lt;P&gt;translated services - original&lt;/P&gt;&lt;P&gt;install on - checkpoint_gateway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see the traffic getting encrypted but the nat isnt getting applied.&amp;nbsp; Anything else im missing?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 18:31:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/50640#M12974</guid>
      <dc:creator>PIAndre</dc:creator>
      <dc:date>2019-04-11T18:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: Nat rule over tunnel/community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/50651#M12975</link>
      <description>&lt;P&gt;There's an option to disable NAT in the VPN Community--see if that's set.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-04-11 at 2.24.44 PM.png" style="width: 615px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/770i70580CBA544D9069/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-04-11 at 2.24.44 PM.png" alt="Screen Shot 2019-04-11 at 2.24.44 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2019 21:25:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/50651#M12975</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-11T21:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: Nat rule over tunnel/community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/50656#M12976</link>
      <description>That did it. Had that box checked and unchecked it. Thanks.</description>
      <pubDate>Thu, 11 Apr 2019 22:37:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/50656#M12976</guid>
      <dc:creator>PIAndre</dc:creator>
      <dc:date>2019-04-11T22:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: Nat rule over tunnel/community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/252913#M49544</link>
      <description>&lt;P&gt;has the issue resolved after doing this changes?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 08:16:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/252913#M49544</guid>
      <dc:creator>Anjan</dc:creator>
      <dc:date>2025-07-10T08:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Nat rule over tunnel/community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/252935#M49549</link>
      <description>&lt;P&gt;Yes, as it clearly indicated by the Solution marked on the recommendation.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 11:58:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Nat-rule-over-tunnel-community/m-p/252935#M49549</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-10T11:58:08Z</dc:date>
    </item>
  </channel>
</rss>

