<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Performing SIC with Mgmt behind NAT in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30441#M2417</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you use&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100583&amp;amp;partition=Advanced&amp;amp;product=Security"&gt;sk100583: Troubleshooting "SmartCenter behind &lt;STRONG&gt;NAT&lt;/STRONG&gt;" issues&lt;/A&gt;&amp;nbsp;? Also, there is&amp;nbsp;the more specialized&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk66381&amp;amp;partition=General&amp;amp;product=Security"&gt;sk66381: How to configure &lt;STRONG&gt;Management&lt;/STRONG&gt; behind &lt;STRONG&gt;NAT&lt;/STRONG&gt; in Security Gateway 80 / 1100 / 1400 Appliance setup&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Feb 2019 12:09:54 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-02-05T12:09:54Z</dc:date>
    <item>
      <title>Performing SIC with Mgmt behind NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30439#M2415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm unable to perform the initial SIC between a gateway and a management behind a NAT. I went through all the posts regarding this matter without success.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've created a dummy object with the NATed IP and created the corresponding NAT rule between the&amp;nbsp;private and NATed IP. The gateway performing the NAT is another Check Point device as well. I've tried with manual static NAT and using the "Add Automatic Address Translation rules" option under the management NAT section without success&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The traffic is allowed in the gateway and I see the logs for the returning traffic as allowed and translated as well correctly, but running a tcpdump in the management&amp;nbsp;the traffic does not reach the management, I only see SYN packets and retransmissions. For some reason the traffic is being consumed by the gateway?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Management runs R80.10 and gateway R77.30.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2019 21:54:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30439#M2415</guid>
      <dc:creator>Antonio_M</dc:creator>
      <dc:date>2019-02-04T21:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Performing SIC with Mgmt behind NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30440#M2416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have any other device in between NAT gateway and management server ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2019 06:16:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30440#M2416</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2019-02-05T06:16:11Z</dc:date>
    </item>
    <item>
      <title>Re: Performing SIC with Mgmt behind NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30441#M2417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you use&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100583&amp;amp;partition=Advanced&amp;amp;product=Security"&gt;sk100583: Troubleshooting "SmartCenter behind &lt;STRONG&gt;NAT&lt;/STRONG&gt;" issues&lt;/A&gt;&amp;nbsp;? Also, there is&amp;nbsp;the more specialized&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk66381&amp;amp;partition=General&amp;amp;product=Security"&gt;sk66381: How to configure &lt;STRONG&gt;Management&lt;/STRONG&gt; behind &lt;STRONG&gt;NAT&lt;/STRONG&gt; in Security Gateway 80 / 1100 / 1400 Appliance setup&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2019 12:09:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30441#M2417</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-02-05T12:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Performing SIC with Mgmt behind NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30442#M2418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, just the Check Point cluster gateways.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2019 20:10:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30442#M2418</guid>
      <dc:creator>Antonio_M</dc:creator>
      <dc:date>2019-02-05T20:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Performing SIC with Mgmt behind NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30443#M2419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I saw both. I tried creating a dummy host with the NAT IP and then creating a manual static NAT and also configuring the NAT properties on the real management object for the dynamic NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I don't understand is why in the auto-created NAT rule, the source and traslated IP address are the same, the internal IP. Shouldn't be the translated IP the specified in the "hide behind IP address"?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2019 20:14:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30443#M2419</guid>
      <dc:creator>Antonio_M</dc:creator>
      <dc:date>2019-02-05T20:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Performing SIC with Mgmt behind NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30444#M2420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What you see in the Automatic NAT rule is the Object of the NATted host, in both Original an Translated column that looks a bit confusing and is one of the reasons why we mostly add the NAT ip in the comment, so that when you hover over the object it will show you both IP's.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2019 21:41:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30444#M2420</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-02-05T21:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: Performing SIC with Mgmt behind NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30445#M2421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I hover over I see the same IP which is the internal one, not the NATted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really frustating this, can't make it work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2019 19:18:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performing-SIC-with-Mgmt-behind-NAT/m-p/30445#M2421</guid>
      <dc:creator>Antonio_M</dc:creator>
      <dc:date>2019-02-06T19:18:36Z</dc:date>
    </item>
  </channel>
</rss>

