<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring NAT translation and snmp traffic in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/153004#M25625</link>
    <description>&lt;P&gt;routing is symmetrical, both objects are in NAT, no ACLs&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jul 2022 14:24:48 GMT</pubDate>
    <dc:creator>Arturxr</dc:creator>
    <dc:date>2022-07-14T14:24:48Z</dc:date>
    <item>
      <title>Configuring NAT translation and snmp traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/152940#M25546</link>
      <description>&lt;P&gt;After setting up NAT snmp translation, traffic goes only one way, there are no answers from the router, while on the router we see its response.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 07:41:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/152940#M25546</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2022-07-14T07:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring NAT translation and snmp traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/152943#M25548</link>
      <description>&lt;P&gt;Do you see the return traffic in a packet capture on the Firewall?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 08:06:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/152943#M25548</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-14T08:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring NAT translation and snmp traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/152947#M25550</link>
      <description>&lt;P&gt;how can we check it?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 08:25:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/152947#M25550</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2022-07-14T08:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring NAT translation and snmp traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/152949#M25560</link>
      <description>&lt;P&gt;Using one of the following tools from the CLI:&lt;/P&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;fw monitor (&lt;SPAN&gt;sk30583&lt;/SPAN&gt;)&lt;/LI&gt;
&lt;LI&gt;cppcap (&lt;SPAN&gt;sk141412&lt;/SPAN&gt;)&lt;/LI&gt;
&lt;LI&gt;tcpdump&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also what service object is used in your rule both to allow the traffic and for the NAT?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 09:08:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/152949#M25560</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-14T09:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring NAT translation and snmp traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/152959#M25590</link>
      <description>&lt;P&gt;reverse traffic is not visible.&lt;/P&gt;&lt;P&gt;attached a screenshot of the objects.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 10:22:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/152959#M25590</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2022-07-14T10:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring NAT translation and snmp traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/152961#M25592</link>
      <description>&lt;P&gt;Please check the routing is symmetric or that there are no ACLs on the router impacting the traffic.&lt;/P&gt;
&lt;P&gt;Both objects are used in the NAT policy?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 11:23:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/152961#M25592</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-14T11:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring NAT translation and snmp traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/153004#M25625</link>
      <description>&lt;P&gt;routing is symmetrical, both objects are in NAT, no ACLs&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 14:24:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/153004#M25625</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2022-07-14T14:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring NAT translation and snmp traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/153096#M25661</link>
      <description>&lt;P&gt;Maybe an ARP issue?&lt;/P&gt;
&lt;P&gt;If you use source NAT (not clear from your post if its source or destination NAT), then there are cases where you have to take care of ARP.&lt;/P&gt;
&lt;P&gt;This is what I mean:&lt;/P&gt;
&lt;P&gt;Simple Topology:&lt;/P&gt;
&lt;P&gt;whatever is behind the router &amp;lt;- ROUTER eth2 (10.0.0.1) &amp;lt;- eth1 (10.0.0.254) GATEWAY eth 2 (172.16.0.1) &amp;lt;- Client (172.16.0.20)&lt;/P&gt;
&lt;P&gt;Example 1:&lt;/P&gt;
&lt;P&gt;You set a source NAT with translating 172.16.0.20 to 10.0.0.254. This will work out of the box.&lt;/P&gt;
&lt;P&gt;Example 2:&lt;/P&gt;
&lt;P&gt;You set a source NAT with translating 172.16.0.20 to 10.0.0.200. This will only work, if you setup 10.0.0.200 as proxy arp address in GAIA for that interface or activated the automatic proxy arp feature. Or you put a static arp entry in your routers ARP table (not recommended). Or you set a route on your router routing 10.0.0.200/32 to 10.0.0.254 (unusual).&lt;/P&gt;
&lt;P&gt;Example 3:&lt;/P&gt;
&lt;P&gt;You set a source NAT with translating 172.16.0.20 to 5.5.5.5. This will only work, if you set a route on your router routing 5.5.5.5/32 to 10.0.0.254.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 13:33:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/153096#M25661</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2022-07-15T13:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring NAT translation and snmp traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/153103#M25664</link>
      <description>&lt;P&gt;Need to investigate why the traffic doesn't reach the gateway, depending on your NAT configuration it might be proxy-ARP issue or a problem elsewhere.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 14:13:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configuring-NAT-translation-and-snmp-traffic/m-p/153103#M25664</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-15T14:13:48Z</dc:date>
    </item>
  </channel>
</rss>

