<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT issue on R77.30 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153844#M25898</link>
    <description>&lt;P&gt;We are using Check Point External interface static NAT .&lt;/P&gt;&lt;P&gt;We are using the same to multiple application on different port, all are working fine, but while doing new NAT for new application its creating issue for all the application.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are crating NAT rule at END .&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jul 2022 12:29:05 GMT</pubDate>
    <dc:creator>puneetbansal</dc:creator>
    <dc:date>2022-07-26T12:29:05Z</dc:date>
    <item>
      <title>NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153838#M25895</link>
      <description>&lt;P&gt;Today i meet with strange issue. Below is the summery .&lt;/P&gt;&lt;P&gt;1. We have Checkpoint firewall cluster in Azure running R77.30 version.&lt;/P&gt;&lt;P&gt;2. There are lot of application working on that firewall using the Policy and NAT ( External Interface NAT ).&lt;/P&gt;&lt;P&gt;3. Today when i created new NAT , all the traffic stopped working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT --&amp;gt; We have to publish new application to internet. We are using FW public IP to host the application on different ports and using NAT traffic is getting redirected to internal private IP on ( http or https)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestion to check , as will not get support from Checkpoint - old version at customer site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 11:11:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153838#M25895</guid>
      <dc:creator>puneetbansal</dc:creator>
      <dc:date>2022-07-26T11:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153839#M25896</link>
      <description>&lt;P&gt;Other than moving to the supported version?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 11:44:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153839#M25896</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-26T11:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153842#M25897</link>
      <description>&lt;P&gt;Are you able to share more about what and how you configured it?&lt;/P&gt;
&lt;P&gt;Eg Auto vs Manual &amp;amp; Static vs Hide.&lt;/P&gt;
&lt;P&gt;Without more info any suggestions will be somewhat limited.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 12:16:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153842#M25897</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-26T12:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153844#M25898</link>
      <description>&lt;P&gt;We are using Check Point External interface static NAT .&lt;/P&gt;&lt;P&gt;We are using the same to multiple application on different port, all are working fine, but while doing new NAT for new application its creating issue for all the application.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are crating NAT rule at END .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 12:29:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153844#M25898</guid>
      <dc:creator>puneetbansal</dc:creator>
      <dc:date>2022-07-26T12:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153845#M25899</link>
      <description>&lt;P&gt;You are correct that you would not get any support from TAC on it, since it is indeed unsupported version. I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;, we need more info as far as whats exactly configured, so we can help you more.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 12:31:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153845#M25899</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-26T12:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153851#M25901</link>
      <description>&lt;P&gt;Are you able to attach a screenshot?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 13:18:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153851#M25901</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-26T13:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153870#M25907</link>
      <description>&lt;P&gt;We're going to need a LOT more information about what the current configuration is, what precise changes you made, and what was observed in the gateway AFTER the change was made with respect to the traffic.&lt;BR /&gt;What was seen in the logs, fw ctl zdebug, etc.&lt;BR /&gt;That said, R77.30 has been End of Support for a while now and your efforts would probably be better spent getting the customer on a more recent version that is supported.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 15:36:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153870#M25907</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-26T15:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153912#M25921</link>
      <description>&lt;P&gt;Thanks PhoneBoy, We are planning to upgrade.&lt;/P&gt;&lt;P&gt;We are doing interface NAT , it seems be due to some bug in R77.30&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="100%" cellspacing="2" cellpadding="4"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;02656968&lt;/TD&gt;&lt;TD&gt;Security Gateway&lt;/TD&gt;&lt;TD&gt;In rare scenarios, when working with Dynamic Objects, NAT rules are not applied anymore after policy installation or update of software blades signatures. This causes traffic outage for all connections that should undergo NAT.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 27 Jul 2022 05:00:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153912#M25921</guid>
      <dc:creator>puneetbansal</dc:creator>
      <dc:date>2022-07-27T05:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153950#M25983</link>
      <description>&lt;P&gt;Resolved almost 5-years ago. Is there no Jumbo installed on this system?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 08:55:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153950#M25983</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-27T08:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153987#M25995</link>
      <description>&lt;P&gt;Nope , We are on Take216 .&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 13:18:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153987#M25995</guid>
      <dc:creator>puneetbansal</dc:creator>
      <dc:date>2022-07-27T13:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153989#M25996</link>
      <description>&lt;P&gt;We took the support of that firewall recently and now we are planning to upgrade.&lt;/P&gt;&lt;P&gt;As the firewall in our support we need to create new rules, but while creating new simple NAT rules ( almost duplicate what we have on firewall almost 90), firewall stopped process all traffic ( even for exiting NAT ) .&lt;/P&gt;&lt;P&gt;Is there any limitation on CP firewall external Interface IP NAT policy in Azure ?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 13:26:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/153989#M25996</guid>
      <dc:creator>puneetbansal</dc:creator>
      <dc:date>2022-07-27T13:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/154009#M26000</link>
      <description>&lt;P&gt;I'll ask my questions again more precisely:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What is the current configuration look like before you started making changes? Screenshots will go a long way here as will a network diagram.&lt;/LI&gt;
&lt;LI&gt;What is the precise configuration change you made? Again, screenshots will go a long way here.&lt;/LI&gt;
&lt;LI&gt;When you say "firewall stopped process all traffic" again what does that mean? Have you done any troubleshooting with tcpdump, fw ctl zdebug, or anything to understand what's going on?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Regardless, I suspect the issue will be resolved by upgrading from R77.30 to a supported release.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 15:03:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/154009#M26000</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-27T15:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/154011#M26002</link>
      <description>&lt;P&gt;The issue you mentioned above is resolved in&amp;nbsp; Take 292 (or higher).&lt;/P&gt;
&lt;P&gt;The only constraint that comes to mind otherwise would be if you're attempting to NAT using well know ports where those are daemons on the Firewall itself.&lt;/P&gt;
&lt;P&gt;More generic concerns would be the volume of ports available for NAT given a single IP is used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 16:15:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/154011#M26002</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-27T16:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/154015#M26004</link>
      <description>&lt;P&gt;As the guys said, we need way more details. Screenshot, config example, at least something that can help us help you. Without it, we cant really do much, and as you know, TAC will never help you, since its totally unsupported version.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;made excellent point...have you done basic debug, tcpdump, fw monitor?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 15:36:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/154015#M26004</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-27T15:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/209617#M39738</link>
      <description>&lt;P&gt;Hello Team ,&lt;BR /&gt;&lt;BR /&gt;User want to access the device from Jump server provided public IP mapped to device Management IP private .Could you please help us how to configure NAT which NAT will be better choice hide nat/Auto Nat/Manual NAT .Checkpoint device version is R77.30 .Appreciate your prompt response&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2024 15:29:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/209617#M39738</guid>
      <dc:creator>mdz</dc:creator>
      <dc:date>2024-03-25T15:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/209681#M39746</link>
      <description>&lt;P&gt;R77.30 is out of support for 15 years now. For your case, you need static NAT to an available public IP address.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 10:08:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/209681#M39746</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-03-26T10:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/209686#M39748</link>
      <description>&lt;P&gt;Why post this here ? This is a very old post and has not much to do with the original issue !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 10:26:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/209686#M39748</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-03-26T10:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: NAT issue on R77.30</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/209690#M39749</link>
      <description>&lt;P&gt;Think of it as port forwarding...say your friend wanted to access your home PC from their place. You would need to add an entry in your home router to forward that traffic, and dst would be whatever internal IP your pc is, so say for rdp port would be 3389&lt;/P&gt;
&lt;P&gt;Lets take same example here...lets pretend that somewhere from the Internet, someone has to reach your internal server on port 789&lt;/P&gt;
&lt;P&gt;rule would be like this for nat:&lt;/P&gt;
&lt;P&gt;original packet:src any, port 789, dst say your external IP&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dst packet: src any, port 789, dst - your internal server&lt;/P&gt;
&lt;P&gt;Makes sense?&lt;/P&gt;
&lt;P&gt;And yes, R77.30 has been unsupported for ages now,please install at least R81, as even R80.40 will be unsupported next month &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 11:27:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-issue-on-R77-30/m-p/209690#M39749</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-03-26T11:27:43Z</dc:date>
    </item>
  </channel>
</rss>

