<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Could not find the exact source IP behind of the Checkpoint in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206955#M39280</link>
    <description>&lt;P&gt;Sorry, I cant see the attachment...can you paste the diagram?&lt;/P&gt;</description>
    <pubDate>Fri, 23 Feb 2024 02:03:15 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-02-23T02:03:15Z</dc:date>
    <item>
      <title>Could not find the exact source IP behind of the Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206944#M39277</link>
      <description>&lt;P&gt;Hello Everyone!&lt;/P&gt;&lt;P&gt;Currently we are facing a rather confusing problem as follows:&lt;/P&gt;&lt;P&gt;1. We have 1 pair of Checkpoint devices and 2 pairs of other vendor's Fw devices connected as shown in the attached image.&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;We use a host with IP 10.0.33.100 located behind the Checkpoint device to access the service on Fw1, traffic goes through a Switch device in the middle. Then we are login to Fw1 device and check the logs on Fw1, we can see source IP 10.0.33.100 connected.&lt;/P&gt;&lt;P&gt;3.&amp;nbsp;We use hosting with IP 10.0.33.100 located behind the Checkpoint device to access the service on Fw2, traffic goes through two Switch devices in the middle. Then we log in to the Fw2 device and check the log on Fw2, we can only see the source IP is Checkpoint's administrative IP, in addition we cannot find any other source IP.&lt;/P&gt;&lt;P&gt;Has anyone had any problems?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 01:40:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206944#M39277</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2024-02-23T01:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: Could not find the exact source IP behind of the Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206950#M39278</link>
      <description>&lt;P&gt;If you have exact source and dst IP, have you tred running fw monitor to see what happens with the traffic?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;also, if say dst is 1.1.1.1 (just replace with right IP), run ip r g 1.1.1.1 from expert mode to see if its taking the correct route.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 01:48:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206950#M39278</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T01:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Could not find the exact source IP behind of the Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206953#M39279</link>
      <description>&lt;P&gt;Traffic when passing through the checkpoint we checked to see that it was on the right route. On the checkpoint we can clearly see the source and dst.&lt;/P&gt;&lt;P&gt;However, as I mentioned, when traffic from a host located behind the checkpoint accesses a host located behind device fw1 through 1 Switch device as shown in the picture I attached, then when we log in to device fw1 and check, we can easily see source is the IP of the host behind the Checkpoint.&lt;/P&gt;&lt;P&gt;However, when traffic from a host located behind the checkpoint accesses a host located behind the fw2 device through 2 Switch device as shown in the picture I attached, then when we log in to the fw2 device and check, we Only seeing the source is the administrative IP of the checkpoint update.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 01:53:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206953#M39279</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2024-02-23T01:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Could not find the exact source IP behind of the Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206955#M39280</link>
      <description>&lt;P&gt;Sorry, I cant see the attachment...can you paste the diagram?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:03:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206955#M39280</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T02:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: Could not find the exact source IP behind of the Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206959#M39281</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-02-23_082926.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24624i0FEA6050547CFF31/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-02-23_082926.png" alt="2024-02-23_082926.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:08:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206959#M39281</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2024-02-23T02:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Could not find the exact source IP behind of the Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206960#M39282</link>
      <description>&lt;P&gt;K, I see it now, ty. Just to make sure, these are 2 single firewalls managede by the same mgmt server?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:27:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206960#M39282</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T02:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: Could not find the exact source IP behind of the Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206964#M39283</link>
      <description>&lt;P&gt;We only have 1 pair of checkpoints configured in Cluster with separate management components.&lt;/P&gt;&lt;P&gt;And fw1 and fw2 are two pairs of firewalls from another vendor.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:39:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206964#M39283</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2024-02-23T02:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: Could not find the exact source IP behind of the Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206965#M39284</link>
      <description>&lt;P&gt;Currently, when logging into the fw2 device to check the logs, we cannot see the exact source IP of the host behind the Checkpoint device. When done, use that host to access the services behind fw2.&lt;/P&gt;&lt;P&gt;We can only see the VIP IP MGMT of the Checkpoint device.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:42:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206965#M39284</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2024-02-23T02:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: Could not find the exact source IP behind of the Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206966#M39285</link>
      <description>&lt;P&gt;K, so its a cluster, got it. Does same issue happen regardless of which fw is the active one?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:51:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206966#M39285</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T02:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: Could not find the exact source IP behind of the Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206968#M39286</link>
      <description>&lt;P&gt;The Cluster Checkpoint device run on mode active/active&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:56:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206968#M39286</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2024-02-23T02:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Could not find the exact source IP behind of the Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206969#M39287</link>
      <description>&lt;P&gt;Did you run zdebug to see if anything is dropped?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 03:00:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/206969#M39287</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T03:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: Could not find the exact source IP behind of the Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/207044#M39288</link>
      <description>&lt;P&gt;From your description it sounds like when you access fw1 the checkpoint don't perform source nat, but when you go to fw2 checkpoint do source nat.&lt;/P&gt;
&lt;P&gt;Did you check the logs on checkpoint for traffic to fw2 and see if indeed you have xlate src and what nat rule does it match?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 17:43:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Could-not-find-the-exact-source-IP-behind-of-the-Checkpoint/m-p/207044#M39288</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-02-23T17:43:36Z</dc:date>
    </item>
  </channel>
</rss>

