<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Return traffic from an internal server is directed to public NAT WAN ip in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-from-an-internal-server-is-directed-to-public-NAT/m-p/162540#M28912</link>
    <description>&lt;P&gt;What is the drop reason? Cannot find it in the log&lt;/P&gt;</description>
    <pubDate>Sat, 19 Nov 2022 10:40:58 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2022-11-19T10:40:58Z</dc:date>
    <item>
      <title>Return traffic from an internal server is directed to public NAT WAN ip</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-from-an-internal-server-is-directed-to-public-NAT/m-p/162534#M28910</link>
      <description>&lt;P&gt;I have a growing number of situations where I am running into this issue where a internal machine is able to reach out but returning traffic destination is showing dropped at my external ip.&lt;BR /&gt;&lt;BR /&gt;I have attached an image of the allowed traffic out, and the drop on my public.&lt;BR /&gt;&lt;BR /&gt;I am curious if the issue may be related to&amp;nbsp;sk114395&lt;BR /&gt;&lt;SPAN&gt;Automatic creation of Proxy ARP for Manual NAT rules on Security Gateway&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114395" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114395&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;In my other instances where i see similar issues, with users attempting to authenticate to a web too out side of our org&lt;BR /&gt;and the users browser is redirected back to our public ip as well.&amp;nbsp;&lt;BR /&gt;I worked with TAC in the past regarding this issue but did not make any progress.&amp;nbsp;&lt;BR /&gt;Working with a consultant on upgrading our blades from 80.30 to 81.10 took a moment and we did see a little improvement adding an entry to the proxy arp on the blade. But the issue continues.&lt;BR /&gt;&lt;BR /&gt;Any thoughts or suggestions regarding this would be much appreciated.&lt;BR /&gt;This hat was handed to me due to the primary leaving the org, please bare with my experience.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;- J&lt;/P&gt;</description>
      <pubDate>Sat, 19 Nov 2022 01:42:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-from-an-internal-server-is-directed-to-public-NAT/m-p/162534#M28910</guid>
      <dc:creator>COE_JW</dc:creator>
      <dc:date>2022-11-19T01:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic from an internal server is directed to public NAT WAN ip</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-from-an-internal-server-is-directed-to-public-NAT/m-p/162540#M28912</link>
      <description>&lt;P&gt;What is the drop reason? Cannot find it in the log&lt;/P&gt;</description>
      <pubDate>Sat, 19 Nov 2022 10:40:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-from-an-internal-server-is-directed-to-public-NAT/m-p/162540#M28912</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-19T10:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic from an internal server is directed to public NAT WAN ip</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-from-an-internal-server-is-directed-to-public-NAT/m-p/162543#M28915</link>
      <description>&lt;P&gt;Does all the correct routing back to the source exist?&lt;/P&gt;
&lt;P&gt;With your NAT policy are there differences between a source network that works vs one that doesn't?&lt;/P&gt;</description>
      <pubDate>Sat, 19 Nov 2022 11:31:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-from-an-internal-server-is-directed-to-public-NAT/m-p/162543#M28915</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-11-19T11:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic from an internal server is directed to public NAT WAN ip</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-from-an-internal-server-is-directed-to-public-NAT/m-p/162548#M28917</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/84882"&gt;@COE_JW&lt;/a&gt; , please advise if:&lt;/P&gt;
&lt;P&gt;1. you are using automatic or manual NAT for the source object.&lt;/P&gt;
&lt;P&gt;2. there are other source objects present with duplicate IPs.&lt;/P&gt;
&lt;P&gt;Additionally, in your screenshot, the packet being dropped is RST-ACK. If session has already timed-out (on Check Point), this will be the expected behavior.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Nov 2022 16:10:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-from-an-internal-server-is-directed-to-public-NAT/m-p/162548#M28917</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-11-19T16:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: Return traffic from an internal server is directed to public NAT WAN ip</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-from-an-internal-server-is-directed-to-public-NAT/m-p/168216#M30429</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/84882"&gt;@COE_JW&lt;/a&gt;&amp;nbsp;I'm with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11879"&gt;@Vladimir&lt;/a&gt;&amp;nbsp;. It appears as though the connection has timed out. Is it just the Azure App Service Migration tool that is having this issue?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 14:23:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Return-traffic-from-an-internal-server-is-directed-to-public-NAT/m-p/168216#M30429</guid>
      <dc:creator>Bryan-Smith</dc:creator>
      <dc:date>2023-01-18T14:23:43Z</dc:date>
    </item>
  </channel>
</rss>

