<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic between internal interaces and hide NAT in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-between-internal-interaces-and-hide-NAT/m-p/142386#M25285</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like a simple topic but still can not confirm it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assuming I have "Automatic address translation" enabled in the object definition with "hide behind the gateway" option. Now, I have 3 interfaces - Internal, External and secondary Internal interface.&lt;/P&gt;&lt;P&gt;Does this nat config apply for the traffic between two internal interfaces? Or hide nat always apply only when traffic exits via the External interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kind regards,&lt;/P&gt;&lt;P&gt;Tomasz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Feb 2022 09:56:46 GMT</pubDate>
    <dc:creator>TT</dc:creator>
    <dc:date>2022-02-24T09:56:46Z</dc:date>
    <item>
      <title>Traffic between internal interaces and hide NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-between-internal-interaces-and-hide-NAT/m-p/142386#M25285</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like a simple topic but still can not confirm it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assuming I have "Automatic address translation" enabled in the object definition with "hide behind the gateway" option. Now, I have 3 interfaces - Internal, External and secondary Internal interface.&lt;/P&gt;&lt;P&gt;Does this nat config apply for the traffic between two internal interfaces? Or hide nat always apply only when traffic exits via the External interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kind regards,&lt;/P&gt;&lt;P&gt;Tomasz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 09:56:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-between-internal-interaces-and-hide-NAT/m-p/142386#M25285</guid>
      <dc:creator>TT</dc:creator>
      <dc:date>2022-02-24T09:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between internal interaces and hide NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-between-internal-interaces-and-hide-NAT/m-p/142398#M25286</link>
      <description>&lt;P&gt;Outgoing traffic from that host/network will only be NAT-ed when being sent out through the external interface.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 11:22:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-between-internal-interaces-and-hide-NAT/m-p/142398#M25286</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-02-24T11:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between internal interaces and hide NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-between-internal-interaces-and-hide-NAT/m-p/142399#M25287</link>
      <description>&lt;P&gt;I'm assuming you are talking about going to the network object itself and configuring its NAT tab.&amp;nbsp; If you look at the 2 automatic NAT rules generated as a result in the NAT policy, the destination of the second generated rule which does the vast majority of the NATting for that network has a destination of "Any".&amp;nbsp; So yes it will NAT that traffic to all other interfaces including the second internal one.&amp;nbsp; Typically you would have a manual anti-NAT/no-NAT rule defined early in the NAT policy that will disable NATting between internal networks and/or DMZs. The first auto-generated rule specifies no-NAT for hairpin/u-turn situations involving that network and is rarely hit.&lt;/P&gt;
&lt;P&gt;I think the checkbox Val is referring to is located on the gateway/cluster object itself on the NAT screen.&amp;nbsp; If you check that one yes only traffic exiting on the External interface will be NATted.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 13:08:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-between-internal-interaces-and-hide-NAT/m-p/142399#M25287</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-02-24T13:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic between internal interaces and hide NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-between-internal-interaces-and-hide-NAT/m-p/142404#M25288</link>
      <description>&lt;P&gt;What&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;told you is always 100% the case.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 14:19:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traffic-between-internal-interaces-and-hide-NAT/m-p/142404#M25288</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-24T14:19:46Z</dc:date>
    </item>
  </channel>
</rss>

