<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can someone please clear my doubts about CP Network? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/154209#M26083</link>
    <description>&lt;P&gt;I was right as it would definitely refers the route.&lt;/P&gt;</description>
    <pubDate>Sat, 30 Jul 2022 03:29:09 GMT</pubDate>
    <dc:creator>Blason_R</dc:creator>
    <dc:date>2022-07-30T03:29:09Z</dc:date>
    <item>
      <title>Can someone please clear my doubts about CP Network?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152223#M25345</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We are planning to use a topology given below.&lt;/P&gt;&lt;P&gt;I am planning to use Check Point default gateway as 1.2.3.5 which is LB. Server 10.10.10.30 is statically manually natted with 1.2.3.7&lt;/P&gt;&lt;P&gt;Proxy ARP added on firewall.&lt;/P&gt;&lt;P&gt;From Check Point perspective I wanted to understand the routing part in the below scenario&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Lets support Traffic is initiated from Internet for host 1.2.3.7 for Port 443&lt;/LI&gt;&lt;LI&gt;It would reach router R1&lt;/LI&gt;&lt;LI&gt;It would Broadcast for ARP. Check Point would send gratuitous ARP&lt;/LI&gt;&lt;LI&gt;Traffic will then be forwarded to 1.2.3.6&lt;/LI&gt;&lt;LI&gt;Traffic will be natted and send out to 10.10.10.30&lt;/LI&gt;&lt;LI&gt;Now while returning from 10.10.10.30&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Once it reached to Check Point&lt;/P&gt;&lt;UL class="lia-list-style-type-circle"&gt;&lt;LI&gt;Does firewall refer to the routing table for destination ANY (Since the packet was originated from Source ANY) and will it be routed to 1.2.3.5; causing asynchronous routing&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;OR&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class="lia-list-style-type-circle"&gt;&lt;LI&gt;Since the firewall already has connection table entry and it knows it arrived from eth0 from 1.2.3.4; will it be routed back to 1.2.3.4?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;My strong feeling is it would definitely be sent it back to 1.2.3.4 since routing is not stateful and I would need to add PBR on CP for source IP&lt;/P&gt;&lt;P&gt;Please advise?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scenario1.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17089iEBB37FA2BA34EA6C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="scenario1.jpg" alt="scenario1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Jul 2022 13:43:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152223#M25345</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-07-03T13:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone please clear my doubts about CP Network?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152229#M25346</link>
      <description>&lt;P&gt;Please clarify the diagram further by specifying subnet masks and is the LB itself performing any NAT?&lt;/P&gt;
&lt;P&gt;Generally the most specific route will be followed.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 04:27:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152229#M25346</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-04T04:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone please clear my doubts about CP Network?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152231#M25347</link>
      <description>&lt;P&gt;You can consider those all are in same network. Lets say /27&lt;/P&gt;&lt;P&gt;Nope Static nat will be configured on Check Point. So that Incoming traffic for Application server will be natted on Check Point firewall and will be forwarded to the server. While Outbound traffic from hosts which is a hide nat will be configured on LB. So the default gateway for Check Point is LB.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 05:50:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152231#M25347</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-07-04T05:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone please clear my doubts about CP Network?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152232#M25348</link>
      <description>&lt;P&gt;Remember connected/specific routes are preferred over the default, so the source you mention probably will have a different behavior in this case if it's part of a /27.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 05:58:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152232#M25348</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-04T05:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone please clear my doubts about CP Network?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152233#M25349</link>
      <description>&lt;P&gt;Yes that I agree and in this scenario - There are no specific routes. I agree least routes will match first and before that even PBRs are matched. However in this scenario; no specific routes are added and only a default gateway is pointed to LB. I am wondering if reverse traffic for statically natted IPs which is a part of established session will it be routed to LB or Router since it know that traffic is received from R1 through eth0&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 06:02:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152233#M25349</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-07-04T06:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone please clear my doubts about CP Network?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152285#M25370</link>
      <description>&lt;P&gt;Are you NATing the source IP too? Does&amp;nbsp; internet host's source IP change when traversing environment via R1?&lt;/P&gt;&lt;P&gt;If not, then I am pretty sure you will have an asymmetric routing issue if your default gateway points to LB, whereby the return traffic from 10.10.10.30 will flick to LB from CP.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 01:57:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152285#M25370</guid>
      <dc:creator>Paul_Kazzi</dc:creator>
      <dc:date>2022-07-05T01:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone please clear my doubts about CP Network?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152287#M25372</link>
      <description>&lt;P&gt;Nope I am not natting Source IP. Source IP is gone be = Original. And I am pretty sure it would cause asymmetric routing issue however wanted to confirm once. Thanks though.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 02:46:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152287#M25372</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-07-05T02:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone please clear my doubts about CP Network?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152289#M25374</link>
      <description>&lt;P&gt;You could test&amp;nbsp; on R1 NATing source IP to an R1 source to force reply back to R1. Obviously subject to testing&amp;nbsp; as unsure of environment specifics &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 03:57:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/152289#M25374</guid>
      <dc:creator>Paul_Kazzi</dc:creator>
      <dc:date>2022-07-05T03:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Can someone please clear my doubts about CP Network?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/154209#M26083</link>
      <description>&lt;P&gt;I was right as it would definitely refers the route.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2022 03:29:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-someone-please-clear-my-doubts-about-CP-Network/m-p/154209#M26083</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-07-30T03:29:09Z</dc:date>
    </item>
  </channel>
</rss>

