<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic One IP address from Network on Cluster and NAT in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-IP-address-from-Network-on-Cluster-and-NAT/m-p/148862#M23827</link>
    <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;We have Cluster with CheckPoint 12600(R77.30). Cluster in Hight Availabilitity mode. And we need to connect to network with subnet 10.1.1.116/30. So, one address 117 configureied to Checkpoint Cluster, other 118 to Gateway to remote network. So I was read this article&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32073&amp;amp;partition=Advanced&amp;amp;product=ClusterXL%22" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32073&amp;amp;partition=Advanced&amp;amp;product=ClusterXL%22&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then I configuried on my nodes interfaces from Network 192.168.0.116/30 and on topology configuried Cluster Interface 10.1.1.117. Then I configuried static routes like this:&lt;/P&gt;&lt;P&gt;10.1.1.116 masklen 30 gateway bond0.997 scopelocal;&lt;/P&gt;&lt;P&gt;172.16.0.1 masklen 32 gateway 10.1.1.118;&lt;/P&gt;&lt;P&gt;I created manual rule for internal network like this:&lt;/P&gt;&lt;P&gt;src: localnet dst: 172.16.0.1 - translate src: 10.1.1.116&lt;/P&gt;&lt;P&gt;src: localnet dst: 10.1.1.116 - translate src: 10.1.1.116&lt;/P&gt;&lt;P&gt;But it is not working - icmp did not answer to this hosts. In logs I can see accepted messgages and in xltsrc i can see NATed address.&lt;/P&gt;&lt;P&gt;How Can I find where is problem?&lt;/P&gt;</description>
    <pubDate>Wed, 18 May 2022 06:53:15 GMT</pubDate>
    <dc:creator>IldarSultanov</dc:creator>
    <dc:date>2022-05-18T06:53:15Z</dc:date>
    <item>
      <title>One IP address from Network on Cluster and NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-IP-address-from-Network-on-Cluster-and-NAT/m-p/148862#M23827</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;We have Cluster with CheckPoint 12600(R77.30). Cluster in Hight Availabilitity mode. And we need to connect to network with subnet 10.1.1.116/30. So, one address 117 configureied to Checkpoint Cluster, other 118 to Gateway to remote network. So I was read this article&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32073&amp;amp;partition=Advanced&amp;amp;product=ClusterXL%22" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32073&amp;amp;partition=Advanced&amp;amp;product=ClusterXL%22&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then I configuried on my nodes interfaces from Network 192.168.0.116/30 and on topology configuried Cluster Interface 10.1.1.117. Then I configuried static routes like this:&lt;/P&gt;&lt;P&gt;10.1.1.116 masklen 30 gateway bond0.997 scopelocal;&lt;/P&gt;&lt;P&gt;172.16.0.1 masklen 32 gateway 10.1.1.118;&lt;/P&gt;&lt;P&gt;I created manual rule for internal network like this:&lt;/P&gt;&lt;P&gt;src: localnet dst: 172.16.0.1 - translate src: 10.1.1.116&lt;/P&gt;&lt;P&gt;src: localnet dst: 10.1.1.116 - translate src: 10.1.1.116&lt;/P&gt;&lt;P&gt;But it is not working - icmp did not answer to this hosts. In logs I can see accepted messgages and in xltsrc i can see NATed address.&lt;/P&gt;&lt;P&gt;How Can I find where is problem?&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 06:53:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-IP-address-from-Network-on-Cluster-and-NAT/m-p/148862#M23827</guid>
      <dc:creator>IldarSultanov</dc:creator>
      <dc:date>2022-05-18T06:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: One IP address from Network on Cluster and NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-IP-address-from-Network-on-Cluster-and-NAT/m-p/148890#M23836</link>
      <description>&lt;P&gt;R77.30 is out of support since September 2019, and the 12600 has only one more month of Support left - so i wonder what you are trying to achieve here as HW/SW is very out of time...&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 11:48:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/One-IP-address-from-Network-on-Cluster-and-NAT/m-p/148890#M23836</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-05-18T11:48:52Z</dc:date>
    </item>
  </channel>
</rss>

