<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it able to set domain objects/groups as destination fro NAT rules ? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-it-able-to-set-domain-objects-groups-as-destination-fro-NAT/m-p/207325#M39202</link>
    <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using R81.20 take 26 as our firewall, and have some NAT rules. All the traffic is routed to Datacenter through a GRE tunnel.&lt;/P&gt;&lt;P&gt;But we still have some traffic needs to bypass the tunnel and NAT to internet directly. In the NAT rules, we use Host Group as destination and all hosts are IP address.&lt;/P&gt;&lt;P&gt;My question is, is it possible to put the Domain Groups ( Domain objects ) into the destination? including FQDN and non-FQDN. As the URL/domains are based on AWS CDN service and the IPs varies.&lt;/P&gt;&lt;P&gt;If it doesn't support, should I use DNS Checker to find out all the IP addresses' public resolution for the domains,&amp;nbsp; and add all the IPs to the destination? That would be a manual work and needs to update frequently if the server's IP changed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks very much&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;</description>
    <pubDate>Tue, 27 Feb 2024 23:46:09 GMT</pubDate>
    <dc:creator>GeorgeF</dc:creator>
    <dc:date>2024-02-27T23:46:09Z</dc:date>
    <item>
      <title>Is it able to set domain objects/groups as destination fro NAT rules ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-it-able-to-set-domain-objects-groups-as-destination-fro-NAT/m-p/207325#M39202</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using R81.20 take 26 as our firewall, and have some NAT rules. All the traffic is routed to Datacenter through a GRE tunnel.&lt;/P&gt;&lt;P&gt;But we still have some traffic needs to bypass the tunnel and NAT to internet directly. In the NAT rules, we use Host Group as destination and all hosts are IP address.&lt;/P&gt;&lt;P&gt;My question is, is it possible to put the Domain Groups ( Domain objects ) into the destination? including FQDN and non-FQDN. As the URL/domains are based on AWS CDN service and the IPs varies.&lt;/P&gt;&lt;P&gt;If it doesn't support, should I use DNS Checker to find out all the IP addresses' public resolution for the domains,&amp;nbsp; and add all the IPs to the destination? That would be a manual work and needs to update frequently if the server's IP changed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks very much&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 23:46:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-it-able-to-set-domain-objects-groups-as-destination-fro-NAT/m-p/207325#M39202</guid>
      <dc:creator>GeorgeF</dc:creator>
      <dc:date>2024-02-27T23:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Is it able to set domain objects/groups as destination fro NAT rules ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-it-able-to-set-domain-objects-groups-as-destination-fro-NAT/m-p/207328#M39203</link>
      <description>&lt;P&gt;I've not tested groups, however the following object types are supported in R81+&lt;/P&gt;
&lt;DIV id="tinyMceEditor_59f538c13e062eChris_Atkinson_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT rules.jpg" style="width: 726px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24664i208CD3E01024EE8B/image-size/large?v=v2&amp;amp;px=999" role="button" title="NAT rules.jpg" alt="NAT rules.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_RN/Topics-RN/Whats-New.htm?tocpath=What%27s%20New%7C_____1#Security_Gateway_and_Gaia" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_RN/Topics-RN/Whats-New.htm?tocpath=What%27s%20New%7C_____1#Security_Gateway_and_Gaia&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 01:06:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-it-able-to-set-domain-objects-groups-as-destination-fro-NAT/m-p/207328#M39203</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-02-28T01:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Is it able to set domain objects/groups as destination fro NAT rules ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-it-able-to-set-domain-objects-groups-as-destination-fro-NAT/m-p/207329#M39204</link>
      <description>&lt;P&gt;All of those work in R81.20, for sure, tested in the lab myself.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 02:48:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Is-it-able-to-set-domain-objects-groups-as-destination-fro-NAT/m-p/207329#M39204</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-28T02:48:33Z</dc:date>
    </item>
  </channel>
</rss>

