<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBR and nat in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207549#M39265</link>
    <description>&lt;P&gt;Use instead of hide behind gateway option the VIP ip of the outgoing interfaces.&lt;/P&gt;
&lt;P&gt;I think you now use automatic NAT, try to make static NAT rule and force it to use correct external IP&lt;/P&gt;</description>
    <pubDate>Fri, 01 Mar 2024 11:58:19 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2024-03-01T11:58:19Z</dc:date>
    <item>
      <title>PBR and nat</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207545#M39262</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I try to find an alternative for isp redundancy with pbr.&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;sk167135&lt;/SPAN&gt;&lt;/SPAN&gt; nearly describes that but for some reason here the internal network has a public-ip network and so there is no need to talk about hide-nat. I tested pbr so far but selecting hide-behind-gateway always uses the interface ip with the default route is used.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 10:52:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207545#M39262</guid>
      <dc:creator>dede79</dc:creator>
      <dc:date>2024-03-01T10:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and nat</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207549#M39265</link>
      <description>&lt;P&gt;Use instead of hide behind gateway option the VIP ip of the outgoing interfaces.&lt;/P&gt;
&lt;P&gt;I think you now use automatic NAT, try to make static NAT rule and force it to use correct external IP&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2024 11:58:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207549#M39265</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-03-01T11:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and nat</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207682#M39321</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;what exactly are you trying to accomplish? going out from specific ISP, without NAT?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so just don't enable NAT on this network object.&lt;/P&gt;
&lt;P&gt;if I didn't understand, please elaborate a bit more.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 03 Mar 2024 16:14:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207682#M39321</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-03-03T16:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and nat</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207688#M39324</link>
      <description>&lt;P&gt;Did you try configuring your NAT manually?&lt;/P&gt;
&lt;P&gt;Dummy object for the NAT with 0.0.0.0 or using Zones may help, but PBR and NAT has some limitations.&lt;/P&gt;
&lt;P&gt;Maybe also explore Quantum SD-WAN with your local SE to see if it can help you?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 00:49:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207688#M39324</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-03-04T00:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and nat</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207694#M39325</link>
      <description>&lt;P&gt;How can I use manuel nat behind Interface upon failover? Alternative for ISP redundancy would require a NAT konfig that works no matter pbr route is active (--&amp;gt; ISP1)&amp;nbsp; or it is down --&amp;gt; (ISP2)&amp;nbsp; -&amp;nbsp; (track pbr routes with monitored IPs)&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 07:47:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207694#M39325</guid>
      <dc:creator>dede79</dc:creator>
      <dc:date>2024-03-04T07:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and nat</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207695#M39326</link>
      <description>&lt;P&gt;As above historically you could use a host object 0.0.0.0 and it would pick the IP of the outbound interface.&lt;/P&gt;
&lt;P&gt;Theoretically you could also assign a different zone to each interface and hence different NAT rules could be specified if needed.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 07:54:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207695#M39326</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-03-04T07:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and nat</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207771#M39341</link>
      <description>&lt;P&gt;You cannot mix PBR and ISP redundancy:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk167135" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk167135&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 19:30:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-nat/m-p/207771#M39341</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-03-04T19:30:50Z</dc:date>
    </item>
  </channel>
</rss>

