<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unstable traffic by NAT. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193199#M35881</link>
    <description>&lt;P&gt;Make sure all options for NAT in global properties are checked.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 21 Sep 2023 00:16:09 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-09-21T00:16:09Z</dc:date>
    <item>
      <title>Unstable traffic by NAT.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193198#M35880</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a strange case.&lt;/P&gt;
&lt;P&gt;I have an access rule, created to consume a domain.&lt;BR /&gt;The rule is working by FQDN (domain object).&lt;/P&gt;
&lt;P&gt;The traffic is intermittent, for port 444 (Sometimes the rule works, and sometimes not).&lt;/P&gt;
&lt;P&gt;When the rule does not work, it is because in the logs, you can see that the traffic at that time, does not NAT, and therefore can not reach the Internet.&lt;/P&gt;
&lt;P&gt;The rule has that sense:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;SRC: 192.168.70.0/0, 192.168.170.0/24, 192.168.130.0/24&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;DST: Domain Object -&amp;gt; ".sunat.gob.pe"&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Services: 80, 8080, 444&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Action: Accepted&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The traffic for the other services like 80, and 8080, work fine, but the "instability" is when they want to consume that destination through port 444.&lt;/P&gt;
&lt;P&gt;Sometimes it works, and sometimes it does not.&lt;/P&gt;
&lt;P&gt;Any idea how to solve this intermittence?&lt;/P&gt;
&lt;P&gt;I share 1 file, which contains the moment, when the rule works correctly, and the moment when the rule does not work.&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 08:50:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193198#M35880</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-03-10T08:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable traffic by NAT.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193199#M35881</link>
      <description>&lt;P&gt;Make sure all options for NAT in global properties are checked.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 00:16:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193199#M35881</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-21T00:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable traffic by NAT.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193202#M35882</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Do you mean this option?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RV2.png" style="width: 825px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22521i2264D897D2F7570E/image-size/large?v=v2&amp;amp;px=999" role="button" title="RV2.png" alt="RV2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Cheers . &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 00:25:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193202#M35882</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-09-21T00:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable traffic by NAT.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193203#M35883</link>
      <description>&lt;P&gt;si senor &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 00:26:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193203#M35883</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-21T00:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable traffic by NAT.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193205#M35884</link>
      <description>&lt;P&gt;The "Global Properties" of the SmartConsole, is as the image you shared.&lt;/P&gt;
&lt;P&gt;What makes me doubt is why the traffic at a certain moment stops doing NAT (this is why the traffic starts to match with the Cleanup Rule).&lt;/P&gt;
&lt;P&gt;This happens at times.&lt;/P&gt;
&lt;P&gt;It is very strange.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 00:38:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193205#M35884</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-09-21T00:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable traffic by NAT.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193206#M35885</link>
      <description>&lt;P&gt;Few times I helped people with this sort of issue, we solved it by clearing nat table. I know its intrusive and has to be done off hours, but seemed to do the trick&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk32224" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk32224&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 00:42:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193206#M35885</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-21T00:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: Unstable traffic by NAT.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193263#M35905</link>
      <description>&lt;P&gt;TAC is probably going to be necessary to get to the bottom of this.&lt;BR /&gt;Not sure why the port would matter here.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 15:37:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unstable-traffic-by-NAT/m-p/193263#M35905</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-21T15:37:00Z</dc:date>
    </item>
  </channel>
</rss>

