<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable NAT-T in Checkpoint GW. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192328#M35540</link>
    <description>&lt;P&gt;I guess keeping it in English is for the best.&lt;/P&gt;&lt;P&gt;The process you described is correct. Once you open the .elg file, you should see what your proposals are.&amp;nbsp; You are one step closer to solving the issue.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Sep 2023 21:33:21 GMT</pubDate>
    <dc:creator>Zolocofxp</dc:creator>
    <dc:date>2023-09-11T21:33:21Z</dc:date>
    <item>
      <title>Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192080#M35464</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Is NAT-T enabled by default on Checkpoint equipment?&lt;/P&gt;
&lt;P&gt;We have a GW, where we have created multiple VPNs with other clients, but specifically, with 1 client (Cisco ASA), we are having communication problems and according to the tests that the endpoint performs, suggests us to "disable" the NAT-T, but this option of disabling the NAT-T in the GW, affects in general to all the VPNs that you have created, right?&lt;/P&gt;
&lt;P&gt;Could someone please confirm this for me.&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 23:38:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192080#M35464</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-09-08T23:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192082#M35466</link>
      <description>&lt;P&gt;Yes, it affects all VPNs that terminate on that gateway.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Sep 2023 01:35:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192082#M35466</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-09T01:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192136#M35479</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;
&lt;P&gt;Is it advisable to disable NAT-T on a Checkpoint GW?&lt;/P&gt;
&lt;P&gt;We have a S2S VPN against a Cisco ASA, but when we work the VPN using a NAT from our side, the other side, fails to see traffic on their equipment.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;Our Real segment: 10.10.100.0/24&lt;BR /&gt;Remote segment: 10.11.1.50/32&lt;BR /&gt;NAT IP from our side: 172.10.15.100/32&lt;/P&gt;
&lt;P&gt;When we use this flow, the remote peer does not see any traffic coming to its side (the tunnel on F1 and F2 are above).&lt;/P&gt;
&lt;P&gt;Cisco ASA, indicates that they have bad experiences with Checkpoint when NAT is used to "hide" the real IPs/Segments, and they relate it to the use of NAT-T that is enabled by default in Checkpoint.&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Sep 2023 19:19:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192136#M35479</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-09-10T19:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192137#M35480</link>
      <description>&lt;P&gt;What option are you referring to bro? You can disable/enable nat per vpn community, its in advanced tab under specific vpn community object.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 10 Sep 2023 22:08:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192137#M35480</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-10T22:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192138#M35481</link>
      <description>&lt;P&gt;I mean disabling NAT-T for a VPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since the remote peer assumes that it is the Checkpoint's NAT-T, which is generating communication problems in phase 2 of the VPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;According to the documentation and PhoneBoy's comment, disabling NAT-T is a global setting that "affects" the entire GW.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But is it advisable to disable this global setting for the GW?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Sep 2023 22:15:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192138#M35481</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-09-10T22:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192139#M35482</link>
      <description>&lt;P&gt;I never seen any global settings for nat-t myself. Only one I know for vpn is one I mentioned.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 10 Sep 2023 22:18:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192139#M35482</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-10T22:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192261#M35518</link>
      <description>&lt;P&gt;There is a gateway-specific setting for NAT-T here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 618px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22411iF57E47E4ED2B112A/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;However, it applies to all VPNs.&lt;BR /&gt;I've never heard of NAT-T itself causing issues with Cisco (though the differences in subnetting can cause issues).&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 17:02:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192261#M35518</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-11T17:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192268#M35520</link>
      <description>&lt;P&gt;You can disable NAT-T for that specific peer using Check Point Database Tool. Especifically, you need to disable it when initiating traffic.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nat.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22416i74AF900BABF75FBD/image-size/large?v=v2&amp;amp;px=999" role="button" title="nat.png" alt="nat.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I suggest you run a VPN Debug, I believe you are having a P2 negotiating issue that could be easily solved.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 17:37:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192268#M35520</guid>
      <dc:creator>Zolocofxp</dc:creator>
      <dc:date>2023-09-11T17:37:41Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192271#M35521</link>
      <description>&lt;P&gt;Thanks for that, totally forgot about that setting &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 17:43:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192271#M35521</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-11T17:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192277#M35523</link>
      <description>&lt;P&gt;The VPN is up and running on both phases, but they do not see the traffic coming to theWe see traffic coming out of the Firewall, and encrypted.&lt;/P&gt;
&lt;P&gt;We have used TCPDUMP, FW MONITOR, and checked the logs, over and over again, the traffic is confirmed to be encrypted coming out of our Checkpoint, but they don't see it "coming in".&lt;/P&gt;
&lt;P&gt;If we work with the real Local IPs, on both sides, they do see the traffic coming in.&lt;/P&gt;
&lt;P&gt;They blame it on the NAT-T of Checkpoint.&lt;/P&gt;
&lt;P&gt;According to the theory, Checkpoint is not the initiator in the NAT-T negotiation, as far as I remember, Checkpoint is normally in "listening" mode for this type of service&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 17:57:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192277#M35523</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-09-11T17:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192286#M35525</link>
      <description>&lt;P&gt;Have both ends send traffic to bring up both phases. In CLI, expert mode, have a look at established tunnel(s) for that peer. There should be only 1 s2s tunnel active with an Out SPI created, Traffic Selector should be /32 for you and your peer. If you see different results, share your findings. We might be able to help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 18:23:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192286#M35525</guid>
      <dc:creator>Zolocofxp</dc:creator>
      <dc:date>2023-09-11T18:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192287#M35526</link>
      <description>&lt;P&gt;You are correct that, in releases prior to R80.10, that Check Point gateways will never initiate NAT-T (except SMB gateways that always have).&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 18:26:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192287#M35526</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-11T18:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192291#M35527</link>
      <description>&lt;P&gt;So, nowadays, in version from R80.20 onwards, the GW Checkpoint, have the ability to "INITIATE" the communication on the NAT-T?&lt;/P&gt;
&lt;P&gt;What is the default behavior of a GW with NAT-T enabled?&lt;BR /&gt;Is it in listening mode, or can it be the one that initiates this traffic?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 18:51:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192291#M35527</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-09-11T18:51:28Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192293#M35528</link>
      <description>&lt;P&gt;Did you confirm nat option inside vpn community?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22418i0554826A1A22C8CB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 18:52:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192293#M35528</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-11T18:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192297#M35529</link>
      <description>&lt;P&gt;On our side, we have 3 segments:&lt;/P&gt;
&lt;P&gt;10.10.120.0/24&lt;BR /&gt;10.10.122.0/24&lt;BR /&gt;10.10.249.0/24&lt;/P&gt;
&lt;P&gt;We use a NAT for these 3 segments:&lt;/P&gt;
&lt;P&gt;IP NAT: 10.11.83.145&lt;/P&gt;
&lt;P&gt;The IPs on the CISCO ASA side are:&lt;/P&gt;
&lt;P&gt;10.11.6.190&lt;BR /&gt;10.11.6.191&lt;BR /&gt;10.11.1.192&lt;/P&gt;
&lt;P&gt;We are doing a Hide NAT.&lt;BR /&gt;&lt;BR /&gt;We have configured the tunnel characteristics in this way.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN2.png" style="width: 752px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22420i0E2EBDC96753F658/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN2.png" alt="VPN2.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Right now, the VPN is "down", since we are not testing right now (I understand that it is down, since the message is NO OUTBOUND SA).&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1.png" style="width: 809px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22419i2C721ACA8CECC0B8/image-size/large?v=v2&amp;amp;px=999" role="button" title="VPN1.png" alt="VPN1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I share the result of a test we did, when the tunnel is up.&lt;BR /&gt;There you can see that the traffic is encrypted, but the other side can not see the traffic on your computer.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 19:06:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192297#M35529</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-09-11T19:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192302#M35530</link>
      <description>&lt;P&gt;I'd still recommend running a Debug to check your proposals. There should be only one tunnel from your NAT IP&amp;nbsp;&lt;SPAN&gt;10.11.83.145/32 to each of peers subnet&amp;nbsp; 10.11.6.x/x and&amp;nbsp;10.11.1.x/x&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Sorry for my awful writing skills btw... I'm a spanish native speaker.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 19:34:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192302#M35530</guid>
      <dc:creator>Zolocofxp</dc:creator>
      <dc:date>2023-09-11T19:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192304#M35531</link>
      <description>&lt;P&gt;I agree with that approach &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 19:41:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192304#M35531</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-11T19:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192315#M35532</link>
      <description>&lt;P&gt;Entonces, mucho mas sencillo, transmitir la idea de mi problema, amigo&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 20:34:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192315#M35532</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-09-11T20:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192320#M35533</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 21:04:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192320#M35533</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-11T21:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Disable NAT-T in Checkpoint GW.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192321#M35534</link>
      <description>&lt;P&gt;In my scenario, what is the appropriate option in the configuration of the&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;"VPN TUNNEL SHARING"&lt;/STRONG&gt; CONFIGURATION?&lt;/P&gt;
&lt;P&gt;Currently, based on my diagram, it is set to &lt;STRONG&gt;"One VPN tunnel per subnet pair"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;This is based on the fact that on our side, we have 3 segments, and on the Cisco ASA side, we have 3 Hosts.&lt;/P&gt;
&lt;P&gt;Is this option the most viable?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 21:06:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-NAT-T-in-Checkpoint-GW/m-p/192321#M35534</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-09-11T21:06:59Z</dc:date>
    </item>
  </channel>
</rss>

