<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS NAT in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-NAT/m-p/54232#M4110</link>
    <description>&lt;P&gt;I understand this config is global to all gateways managed by the same management server, right?&lt;/P&gt;&lt;P&gt;Is there a way to enable DNS NAT for only one gateway?&lt;/P&gt;&lt;P&gt;Or for a subset of NAT rules?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 May 2019 12:57:57 GMT</pubDate>
    <dc:creator>Louis_Poulin</dc:creator>
    <dc:date>2019-05-23T12:57:57Z</dc:date>
    <item>
      <title>DNS NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-NAT/m-p/36593#M2972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've a problem. We have a device which sends the dns requests to the external Zone. The problem is that for establishing a cluster it wants to revolve it's own hostname and expects the local interface IP as response... but because it requests the external zone it gets a public IP.. so my quetion is: Is there a way to rewrite the DNS answer from the public IP to the internal IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've seen the DNS NAT feature but to be honest - I've no glue what this thing does after I've changes the global setting in tha database..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2018 07:34:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-NAT/m-p/36593#M2972</guid>
      <dc:creator>Robert_Mueller</dc:creator>
      <dc:date>2018-03-20T07:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: DNS NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-NAT/m-p/36594#M2973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume you're referring to this:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34295" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34295"&gt;How to configure DNS NAT&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What this basically does is utilizes the existing NAT rules to also translate DNS requests.&lt;/P&gt;&lt;P&gt;Specifically:&amp;nbsp;DNS traffic (DNS Requests) will be translated based on the Destination address in the NAT rules without considering the Source of the traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That means:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;There must be a NAT rule where the public IP address is the original destination&lt;/LI&gt;&lt;LI&gt;The translated destination for this rule would be&amp;nbsp;the internal IP&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2018 17:27:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-NAT/m-p/36594#M2973</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-20T17:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: DNS NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-NAT/m-p/36595#M2974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thx - I've found that SK but what happens with existing NAT Rules - will there also a "NAT Translation" performed?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 07:59:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-NAT/m-p/36595#M2974</guid>
      <dc:creator>Robert_Mueller</dc:creator>
      <dc:date>2018-03-21T07:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: DNS NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-NAT/m-p/36596#M2975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As Dameon wrote, this feature will use the existing NAT rules, but " without considering the Source of the traffic", so the given config example should work. Apart from DNS, NAT should work as before.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 11:19:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-NAT/m-p/36596#M2975</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-21T11:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: DNS NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-NAT/m-p/54232#M4110</link>
      <description>&lt;P&gt;I understand this config is global to all gateways managed by the same management server, right?&lt;/P&gt;&lt;P&gt;Is there a way to enable DNS NAT for only one gateway?&lt;/P&gt;&lt;P&gt;Or for a subset of NAT rules?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2019 12:57:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/DNS-NAT/m-p/54232#M4110</guid>
      <dc:creator>Louis_Poulin</dc:creator>
      <dc:date>2019-05-23T12:57:57Z</dc:date>
    </item>
  </channel>
</rss>

