<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Timeout in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Timeout/m-p/128227#M18662</link>
    <description>&lt;P&gt;What value is being displayed by this command:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fw ctl get int&amp;nbsp;fwx_nat_dynamic_port_allocation_entry_timeout&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;It should display 120 seconds, which is how long the firewall is supposed to wait before reusing a Hide NAT source IP/source port combo, see&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103656&amp;amp;partition=Basic&amp;amp;product=CoreXL" target="_blank"&gt;sk103656: Dynamic NAT port allocation feature&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Aug 2021 11:54:51 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2021-08-27T11:54:51Z</dc:date>
    <item>
      <title>NAT Timeout</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Timeout/m-p/128222#M18661</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;Platform:&amp;nbsp; &amp;nbsp;ClusterXL (Two 15600 Gateways)&amp;nbsp; &amp;nbsp;Active/Passive&lt;/P&gt;&lt;P&gt;Version:&amp;nbsp; &amp;nbsp; R80.10&lt;/P&gt;&lt;P&gt;In the internet traffic in which I perform translation whit one public-IP (PAT) in a NAT policy, I observe the following:&lt;/P&gt;&lt;P&gt;Same combination of Tranlated-Source.IP-address + Tranlated-Source-Port (different Dest.Address) is used few seconds after is used in another TCP session.&lt;/P&gt;&lt;P&gt;Do you know haw can I verify the NAT timeout (time after the gateway can use the same "Tranlated-Source.IP-address + Tranlated-Source-Port")?&lt;/P&gt;&lt;P&gt;Can I change thie timeout or change this behabiour?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;In the file attached, same Tranlated-Source.IP-address and Tranlated-Source-Port are used every few seconds, at:&lt;/P&gt;&lt;P&gt;12:39:13&lt;BR /&gt;12:39:10&lt;BR /&gt;12:39:05&lt;/P&gt;&lt;P&gt;I need to avoid that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 10:23:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Timeout/m-p/128222#M18661</guid>
      <dc:creator>GregorioLujan</dc:creator>
      <dc:date>2021-08-27T10:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Timeout</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Timeout/m-p/128227#M18662</link>
      <description>&lt;P&gt;What value is being displayed by this command:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fw ctl get int&amp;nbsp;fwx_nat_dynamic_port_allocation_entry_timeout&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;It should display 120 seconds, which is how long the firewall is supposed to wait before reusing a Hide NAT source IP/source port combo, see&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103656&amp;amp;partition=Basic&amp;amp;product=CoreXL" target="_blank"&gt;sk103656: Dynamic NAT port allocation feature&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 11:54:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Timeout/m-p/128227#M18662</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-08-27T11:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Timeout</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Timeout/m-p/128315#M18682</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;Thank you very much Timothy for reply.&lt;/P&gt;&lt;P&gt;The output is 120 seconds.&lt;BR /&gt;"fwx_nat_dynamic_port_allocation_entry_timeout = 120"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;As I understand it, "Dynamic NAT port allocation" is not enabled in my gateways:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;For R80.10&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;Note: When the Number of CoreXL FW instances is less than 6, the Dynamic NAT port allocation is disabled by default.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;fwx_nat_dynamic_port_allocation&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;On versions R80.10 and above: 1 - enable dynamic NAT port allocation only when the number of CoreXL FW instances is greater than 5&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Output for "fw ctl get int fwx_nat_dynamic_port_allocation" &amp;gt;&amp;gt; fwx_nat_dynamic_port_allocation = 1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;And I supose the value of "fwx_nat_dynamic_port_allocation_entry_timeout" (120 secods), aply when Dynamic NAT port allocation is enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;On the other hand, I am not sure if the value of "fwx_nat_dynamic_port_allocation_entry_timeout" [Amount of time (in seconds) the Security Gateway will wait before reusing old/previously used ports] aply only to the connecions to the same destination IP address:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;"The ranges are also keyed by the Destination IP address, so each Destination IP address gets a separate allocation."&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;In my case, I need to the gateway not use the same port even if it is to a different address, at least until after a few minutes if possible&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you, regards.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 07:17:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Timeout/m-p/128315#M18682</guid>
      <dc:creator>GregorioLujan</dc:creator>
      <dc:date>2021-08-30T07:17:04Z</dc:date>
    </item>
  </channel>
</rss>

