<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec with NAT in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-with-NAT/m-p/201440#M37899</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;Thank you for the reply.&lt;BR /&gt;&lt;BR /&gt;One thing to keep in mind, the service worked/reachable when we allow server to server without NAT on the Encryption Domain. But with NAT it will not work.&lt;BR /&gt;&lt;BR /&gt;Below you will the excluded services screenshot form the community.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 24 Dec 2023 06:17:30 GMT</pubDate>
    <dc:creator>gemechisd</dc:creator>
    <dc:date>2023-12-24T06:17:30Z</dc:date>
    <item>
      <title>IPSec with NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-with-NAT/m-p/201062#M37782</link>
      <description>&lt;P&gt;We have a checkpoint security gateway with R81.10 JHF 110 Installed. And we have established a Site to Site IPSec VPN with one partner having Fortigate Firewall. On the established IPSec tunnel we have 3 different Encryption Domains for different services. The third party wants our encryption domains to be natted to an IP Address they gave us. We have done the nat of our local encryption domains for the 3 services with different NAT IP's. And we can reach 2 services to the Remote destination / Encryption Domain, but we can't reach 1 service on the remote ED. All three services are on the same IPSec VPN Tunnel.&lt;BR /&gt;&lt;BR /&gt;Why is 2 services with Natted IP's worked and 1 service is not working for us?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 13:44:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-with-NAT/m-p/201062#M37782</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-12-19T13:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec with NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-with-NAT/m-p/201066#M37784</link>
      <description>&lt;P&gt;K, so sounds like config is fine. If one is failing, maybe do basic VPN debug and also check vpnd.elg files as well for that service. Out of curiosity, what service is it? Make sure its not expluded in the excluded services tab on the community options as per below.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23725i761A7B018B3C3B4D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 14:02:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-with-NAT/m-p/201066#M37784</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-19T14:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec with NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-with-NAT/m-p/201440#M37899</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;Thank you for the reply.&lt;BR /&gt;&lt;BR /&gt;One thing to keep in mind, the service worked/reachable when we allow server to server without NAT on the Encryption Domain. But with NAT it will not work.&lt;BR /&gt;&lt;BR /&gt;Below you will the excluded services screenshot form the community.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Dec 2023 06:17:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-with-NAT/m-p/201440#M37899</guid>
      <dc:creator>gemechisd</dc:creator>
      <dc:date>2023-12-24T06:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec with NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-with-NAT/m-p/201448#M37901</link>
      <description>&lt;P&gt;Might be worth TAC case to double check.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 24 Dec 2023 12:42:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-with-NAT/m-p/201448#M37901</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-24T12:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec with NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-with-NAT/m-p/201541#M37911</link>
      <description>&lt;P&gt;What are the precise details of the NAT you've configured on your end, working and non-working?&lt;BR /&gt;Possible this is an issue on the remote end.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Dec 2023 18:41:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSec-with-NAT/m-p/201541#M37911</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-26T18:41:01Z</dc:date>
    </item>
  </channel>
</rss>

