<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is NAT required for a ClusterXL vip outbound? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/146632#M23304</link>
    <description>&lt;P&gt;There is an option in the gateway object to hide behind the gateway IP.&lt;BR /&gt;Is that checked?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Apr 2022 21:46:42 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-04-20T21:46:42Z</dc:date>
    <item>
      <title>Is NAT required for a ClusterXL vip outbound?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/146625#M23298</link>
      <description>&lt;P&gt;I just setup a brand new ClusterXL security gateway. eth0 has a WAN facing ip as it's VIP, say X.X.X.X/30. I&lt;SPAN&gt;t's a public /30, with the router ahead of me holding 1 of 2 other IPs. so the the non-virtual IPs on that interface are on 172.17.0.0/30.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Just trying to get some basic routing going.&lt;/P&gt;&lt;P&gt;When I ping X.X.X.X from the outside, I see it hit the FW. Be allowed but NAT'ed to 1 of the 172.17.0.0s and no reply is received by the remote end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Outbound, if I ssh into one of the gateways, for starters I cannot ping -I X.X.X.X/30 8.8.8.8. It says cannot assign requested address. Maybe this is expected.&lt;/P&gt;&lt;P&gt;A regular attempt at a ping is also seen on the firewall but get's NAT'ed to the the Cluster VIP of my management network (Y.Y.Y.Y/24). No reply is seen on my end here either.&lt;/P&gt;&lt;P&gt;Both show up as NAT Rule Number 0.&lt;/P&gt;&lt;P&gt;eth0 is defined as the only external in topology&lt;/P&gt;&lt;P&gt;ICMP Requests in Global Properties are checked on.&lt;/P&gt;&lt;P&gt;Surely, NAT isn't required here when its meant for hosts BEHIND the gateway, no?&lt;/P&gt;&lt;P&gt;I feel like I'm missing something.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 19:34:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/146625#M23298</guid>
      <dc:creator>Rob_Shears</dc:creator>
      <dc:date>2022-04-20T19:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Is NAT required for a ClusterXL vip outbound?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/146627#M23303</link>
      <description>&lt;P&gt;Well, for outbound access, it has to be natted, otherwise, clients wont be able to access the Internet with non-routable IP address. Now, for inbound, you need static NAT. Or am I missing totally whats not working here?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 19:50:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/146627#M23303</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-20T19:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Is NAT required for a ClusterXL vip outbound?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/146632#M23304</link>
      <description>&lt;P&gt;There is an option in the gateway object to hide behind the gateway IP.&lt;BR /&gt;Is that checked?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 21:46:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/146632#M23304</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-04-20T21:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is NAT required for a ClusterXL vip outbound?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/146633#M23305</link>
      <description>&lt;P&gt;This is landing on the CP gateway itself (its WAN address) or in the 2nd ecample, direct from the CP gateway.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 22:15:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/146633#M23305</guid>
      <dc:creator>Rob_Shears</dc:creator>
      <dc:date>2022-04-20T22:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Is NAT required for a ClusterXL vip outbound?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/146634#M23306</link>
      <description>&lt;P&gt;Yes i tried checking it but it made no difference. i also dont understand why NAT would be required from the CP gateway holding the IP in question itself.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 22:16:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/146634#M23306</guid>
      <dc:creator>Rob_Shears</dc:creator>
      <dc:date>2022-04-20T22:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is NAT required for a ClusterXL vip outbound?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/146635#M23307</link>
      <description>&lt;P&gt;K...can you please give us an example of EXACTLY what is not working? Either inbound or outbound? Basic network topology/diagram would also help.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 22:18:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/146635#M23307</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-20T22:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: Is NAT required for a ClusterXL vip outbound?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/147076#M23426</link>
      <description>&lt;P&gt;I cannot ping the gateway ClusterXL VIP.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Diagram:&lt;BR /&gt;&lt;IMG src="https://i.imgur.com/igP2OMO.png" border="0" /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Traffic is seen in the firewall log as accepted, but no reply is received:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Rob_Shears_1-1650979388775.png" style="width: 708px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16193i458424332E2B4AAB/image-dimensions/708x23?v=v2" width="708" height="23" role="button" title="Rob_Shears_1-1650979388775.png" alt="Rob_Shears_1-1650979388775.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Output of:&amp;nbsp;fw monitor -e 'accept(src=82.X.X.249 or dst=82.X.X.249);'&lt;BR /&gt;&lt;BR /&gt;&lt;IMG src="https://i.imgur.com/hBVExBb.png" border="0" /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pinging 82.X.X.249 from the security gateway itself using: ping -I eth0 82.X.X.249 DOES work.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 13:57:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/147076#M23426</guid>
      <dc:creator>Rob_Shears</dc:creator>
      <dc:date>2022-04-26T13:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: Is NAT required for a ClusterXL vip outbound?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/147078#M23428</link>
      <description>&lt;P&gt;Just run fw ctl zdebug + drop | grep x.x.x.x on the ssh and see what you get. Replace with proper IP address.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 13:32:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/147078#M23428</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-26T13:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is NAT required for a ClusterXL vip outbound?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/147081#M23429</link>
      <description>&lt;P&gt;not seeing any drops for icmp.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 13:48:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/147081#M23429</guid>
      <dc:creator>Rob_Shears</dc:creator>
      <dc:date>2022-04-26T13:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is NAT required for a ClusterXL vip outbound?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/147092#M23434</link>
      <description>&lt;P&gt;Having tried a similar IP scheme with a PFSense Clone - i know it works.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 15:35:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/147092#M23434</guid>
      <dc:creator>Rob_Shears</dc:creator>
      <dc:date>2022-04-26T15:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Is NAT required for a ClusterXL vip outbound?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/147094#M23436</link>
      <description>&lt;P&gt;Right so now I'm a little confused on how clustering is supposed to work.&lt;BR /&gt;&lt;BR /&gt;&lt;IMG src="https://i.imgur.com/vn4BDXD.png" border="0" /&gt;&lt;BR /&gt;&lt;BR /&gt;This was enough to see some public TCP traffic arriving on the Checkpoint. But I was unable to ping outside-&amp;gt; inside or vice versa. I also saw a change in Gaia's "routing monitor" once this was configured in SmartConsole.&lt;BR /&gt;&lt;BR /&gt;In a dire attempt, I added the 82.x.x8.250/30 to Gaia Web UI as an alias to eth0 on cp-gw-1 and it now appears to be working w/ cp-gw-2 shut down.&lt;/P&gt;&lt;P&gt;But this is a virtual IP in a /30 (meaning only 2 addresses, one of which is my default g/w). How could I possibly assign the same alias to cp-gw-2 w/out them clashing?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 16:05:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/147094#M23436</guid>
      <dc:creator>Rob_Shears</dc:creator>
      <dc:date>2022-04-26T16:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is NAT required for a ClusterXL vip outbound?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/147113#M23437</link>
      <description>&lt;P&gt;I'm trying to follow this to the letter now to workaround the issue:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32073" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32073&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;After setting scopelocal, I can ping the upstream gateway (82.x.x8.249) from internal clients, but can't reach past that. I get "IP routing failed (ipout routing failure)".&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It appears that my default route isn't entering the route table:&lt;BR /&gt;&lt;BR /&gt;&lt;IMG src="https://i.imgur.com/5cr4l8d.png" border="0" /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Edit: after reading the SK and this thread:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/ClusterXL-Different-Subnet-Configuration/td-p/8020" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/ClusterXL-Different-Subnet-Configuration/td-p/8020&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I rebooted and things started working.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 21:32:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-NAT-required-for-a-ClusterXL-vip-outbound/m-p/147113#M23437</guid>
      <dc:creator>Rob_Shears</dc:creator>
      <dc:date>2022-04-26T21:32:08Z</dc:date>
    </item>
  </channel>
</rss>

