<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable NAT Traversal per VPN community in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enable-NAT-Traversal-per-VPN-community/m-p/130318#M19139</link>
    <description>&lt;P&gt;Is there a way to enable the support for NAT-T per community, and not globally for a gateway / cluster?&lt;/P&gt;&lt;P&gt;We have found, for what ever reason, that enabling this feature globally has caused some VPN tunnels, where neither end is behind a NAT device, to fail.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Sep 2021 08:52:49 GMT</pubDate>
    <dc:creator>Michael_Horne</dc:creator>
    <dc:date>2021-09-27T08:52:49Z</dc:date>
    <item>
      <title>Enable NAT Traversal per VPN community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enable-NAT-Traversal-per-VPN-community/m-p/130316#M19137</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;Is there a supported way to enable NAT-T for a specific VPN community only?&lt;/P&gt;&lt;P&gt;As far as I can tell NAT-T can only be activated via SmartConsole for the entire gateway / cluster.&amp;nbsp; We have one VPN issue, where the remote party is saying that enabling NAT-T will solve the issue. We have had problems in the past when enabling NAT-T on a gateway cluster where the remote end of the VPN will try NAT-T and the checkpoint doesn't and neither end will switch over to use the method of the other gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We do not want to enable NAT-T on the gateway / cluster for the this Site to site VPN, due to the risk of breaking some of the already existing VPN tunnels.&lt;/P&gt;&lt;P&gt;We would prefer to enable NAT-T for the specific VPN community for testing. if this was possible.&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 08:37:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enable-NAT-Traversal-per-VPN-community/m-p/130316#M19137</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2021-09-27T08:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: Enable NAT Traversal per VPN community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enable-NAT-Traversal-per-VPN-community/m-p/130317#M19138</link>
      <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104760&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk104760: ATRG: VPN Core&lt;/A&gt;:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Check Point VPN clients and SMB appliances (600/700/1100/1200R/1400/Edge) will initiate a negotiation with NAT-D payload, so NAT-T can be agreed on. However, Security Gateways currently support responding to negotiation with NAT-D payload, but do not initiate NAT-D themselves.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 08:44:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enable-NAT-Traversal-per-VPN-community/m-p/130317#M19138</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-09-27T08:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: Enable NAT Traversal per VPN community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enable-NAT-Traversal-per-VPN-community/m-p/130318#M19139</link>
      <description>&lt;P&gt;Is there a way to enable the support for NAT-T per community, and not globally for a gateway / cluster?&lt;/P&gt;&lt;P&gt;We have found, for what ever reason, that enabling this feature globally has caused some VPN tunnels, where neither end is behind a NAT device, to fail.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 08:52:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enable-NAT-Traversal-per-VPN-community/m-p/130318#M19139</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2021-09-27T08:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: Enable NAT Traversal per VPN community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enable-NAT-Traversal-per-VPN-community/m-p/130321#M19140</link>
      <description>&lt;P&gt;You can only disable answering to NAT-D per &amp;#30;GW&amp;nbsp;in IP Sec VPN - VPN Advanced, but not per community.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 11:14:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enable-NAT-Traversal-per-VPN-community/m-p/130321#M19140</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-09-27T11:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: Enable NAT Traversal per VPN community</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enable-NAT-Traversal-per-VPN-community/m-p/130324#M19141</link>
      <description>&lt;P&gt;&lt;SPAN&gt;sk32664 tells us:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Pre-R80.10&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Check Point Security Gateways only supports &lt;STRONG&gt;answering&lt;/STRONG&gt; to NAT-T proposals from the peer side gateway when all of the following conditions are met:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The peer gateway has to be a "dynamic" gateway without a fixed IP address.&lt;/LI&gt;
&lt;LI&gt;Certificate-based authentication must be used for the VPN community.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The remote end has to initiate the NAT-T request.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Since R80.10 it is possible to change the behaviour and make CP GWs initiate NAT-T, but this is not the default.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 11:15:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Enable-NAT-Traversal-per-VPN-community/m-p/130324#M19141</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-09-27T11:15:37Z</dc:date>
    </item>
  </channel>
</rss>

