<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Uturn Nat Firewall Checkpoint in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uturn-Nat-Firewall-Checkpoint/m-p/172940#M31433</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/89917"&gt;@CheckGatzMet&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So per my understanding, you're trying to do the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- when you try to reach&amp;nbsp;&lt;SPAN&gt;200.200.200.200.10 from LAN side clients&amp;nbsp;10.10.10.100 you show as coming from DMZ&amp;nbsp;172.10.10.100 .&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That I have to try, but I think it's doable, the only problem that I would see, is that you would might have some spoofing alerts/errors.&lt;BR /&gt;&lt;BR /&gt;You can do the NAT rule, on specific port, and see how it goes, and that NAT rule needs to be on TOP of all others, or almost on top of them, depending how you have the NAT layered...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;PS: we have similar NAT rules, but not 100% like in your scenario, and works well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 28 Feb 2023 06:25:57 GMT</pubDate>
    <dc:creator>Sorin_Gogean</dc:creator>
    <dc:date>2023-02-28T06:25:57Z</dc:date>
    <item>
      <title>Uturn Nat Firewall Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uturn-Nat-Firewall-Checkpoint/m-p/172420#M31332</link>
      <description>&lt;P class=""&gt;Uturn Nat Firewall Checkpoint&lt;/P&gt;&lt;P class=""&gt;Hello good evening, first of all, thank you for your time, good vibes and your collaboration.&lt;/P&gt;&lt;P class=""&gt;-How can I configure a DNAT U-turn NAT on Checkpoint firewalls ?&lt;/P&gt;&lt;P class=""&gt;That is to say that in a scheme like the following:&lt;/P&gt;&lt;P class=""&gt;Checkpoint Interfaces: Internet 200.200.200.200.10/28 - DMZ 172.10.10.0/25 - LAN Users: 10.10.10.0/24.&lt;/P&gt;&lt;P class=""&gt;-The DNAT all OK from the public IP against the DMZ, from Interrnet.&lt;/P&gt;&lt;P class=""&gt;Now how can I configure a Uturn NAT, that is to say that from the LAN Users, a user with IP 10.10.10.100 connects to the 200.200.200.10 and DNAT is applied against the Ip of the DMZ 172.10.10.100.&lt;/P&gt;&lt;P class=""&gt;Thanks in advance for your comments, tips, etc.&lt;/P&gt;&lt;P class=""&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 06:24:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uturn-Nat-Firewall-Checkpoint/m-p/172420#M31332</guid>
      <dc:creator>CheckGatzMet</dc:creator>
      <dc:date>2023-02-23T06:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: Uturn Nat Firewall Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uturn-Nat-Firewall-Checkpoint/m-p/172865#M31427</link>
      <description>&lt;P&gt;Since the traffic has to traverse the gateway to get to the Internet and any traffic from the DMZ also traverses the gateway, this really isn't U-turn NAT.&lt;BR /&gt;In any case, you configure manual NAT rules with the explicit source LAN, destination, and translated source IP (specifically DMZ) as a HIDE address.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 18:29:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uturn-Nat-Firewall-Checkpoint/m-p/172865#M31427</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-27T18:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Uturn Nat Firewall Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uturn-Nat-Firewall-Checkpoint/m-p/172872#M31428</link>
      <description>&lt;P&gt;Learned something new today...only U-turn I ever knew was with a car lol. Anyway, reading about it online, I see the point&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;made, makes sense.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 19:13:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uturn-Nat-Firewall-Checkpoint/m-p/172872#M31428</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-27T19:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Uturn Nat Firewall Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uturn-Nat-Firewall-Checkpoint/m-p/172932#M31432</link>
      <description>&lt;P&gt;Hello, thanks a lot for your comments&lt;/P&gt;&lt;P&gt;Both Cisco firewalls, Palo Alto, among others, name this type of communication, this type of NATs, as U-TURN others as Hairpin.&lt;/P&gt;&lt;P&gt;In fact you can look it up in the "sk110019", where Checkpoint details its configuration, it names it as Hairpin NAT / NAT Reflection.&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110019" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110019&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 02:14:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uturn-Nat-Firewall-Checkpoint/m-p/172932#M31432</guid>
      <dc:creator>CheckGatzMet</dc:creator>
      <dc:date>2023-02-28T02:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Uturn Nat Firewall Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uturn-Nat-Firewall-Checkpoint/m-p/172940#M31433</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/89917"&gt;@CheckGatzMet&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So per my understanding, you're trying to do the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- when you try to reach&amp;nbsp;&lt;SPAN&gt;200.200.200.200.10 from LAN side clients&amp;nbsp;10.10.10.100 you show as coming from DMZ&amp;nbsp;172.10.10.100 .&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That I have to try, but I think it's doable, the only problem that I would see, is that you would might have some spoofing alerts/errors.&lt;BR /&gt;&lt;BR /&gt;You can do the NAT rule, on specific port, and see how it goes, and that NAT rule needs to be on TOP of all others, or almost on top of them, depending how you have the NAT layered...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;PS: we have similar NAT rules, but not 100% like in your scenario, and works well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 06:25:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Uturn-Nat-Firewall-Checkpoint/m-p/172940#M31433</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2023-02-28T06:25:57Z</dc:date>
    </item>
  </channel>
</rss>

