<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 3600 - NAT port forwarding with WAN DHCP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/218007#M41560</link>
    <description>&lt;P&gt;MDPS is not relevant for standalone systems.&lt;BR /&gt;Did you try enabling DAIP as described here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk166225" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk166225&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;I don't think you can enable it in SmartConsole since this is a standalone system, which I don't believe support DAIP.&lt;BR /&gt;However, this might enable updating of the LocalMachine object if you have one of your interfaces defined as dynamic.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jun 2024 19:50:58 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-06-18T19:50:58Z</dc:date>
    <item>
      <title>3600 - NAT port forwarding with WAN DHCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217648#M41477</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Have an standalone 3600.&lt;/P&gt;&lt;P&gt;One external interface connected to ISP, public-ip is assigned by dhcp.&lt;BR /&gt;Another interface is connected to LAN switches and created vlan subinterfaces as default gw for internal networks.&lt;/P&gt;&lt;P&gt;Some servers need to have incoming port forwarding for their services. Have little CP experience, this is now migrated from Palo Alto.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My issue is dynamic public-ip, how could I create fw/nat rules that is using the external interface ip?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;It's working when I manually create an host object with the current public-ip.&lt;/P&gt;&lt;P&gt;Outgoing hide-nat is done by "Add automatic address translation rules"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp1.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26275iAFF5485D7B7E058A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cp1.PNG" alt="cp1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp-rule.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26276iFA04DB8FCDAD95EA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cp-rule.PNG" alt="cp-rule.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jun 2024 11:07:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217648#M41477</guid>
      <dc:creator>Checkper</dc:creator>
      <dc:date>2024-06-16T11:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 - NAT port forwarding with WAN DHCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217844#M41524</link>
      <description>&lt;P&gt;Create manual rules in terms of the object LocalMachine.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 22:57:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217844#M41524</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-17T22:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 - NAT port forwarding with WAN DHCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217885#M41542</link>
      <description>&lt;P&gt;Yes, already tried LocalMachine without success.&lt;BR /&gt;&lt;SPAN&gt;Seems that incoming traffic is not hitting the NAT rule anymore.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is it possible to see the value of LocalMachine object?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Reading about dynamic objects now and scripts... not sure that is a good solution&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 05:06:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217885#M41542</guid>
      <dc:creator>Checkper</dc:creator>
      <dc:date>2024-06-18T05:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 - NAT port forwarding with WAN DHCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217977#M41556</link>
      <description>&lt;P&gt;LocalMachine is a dynamic object we manage.&lt;BR /&gt;You can use the dynamic_objects CLI command to see the current contents of any given dynamic object.&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_CLI_ReferenceGuide/Content/Topics-CLIG/FWG/dynamic_objects.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_CLI_ReferenceGuide/Content/Topics-CLIG/FWG/dynamic_objects.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 15:16:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217977#M41556</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-18T15:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 - NAT port forwarding with WAN DHCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217983#M41557</link>
      <description>&lt;P&gt;What about a security zone and manual NAT:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Security-Zones.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Security-Zones.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Never tried that myself, though.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 15:31:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217983#M41557</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-06-18T15:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 - NAT port forwarding with WAN DHCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217992#M41558</link>
      <description>&lt;P&gt;Good tip, but seems that zones cannot be used when Translated Destination need to be changed from "Original" (Local server ip)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="validate_err.PNG" style="width: 216px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26338iFAA6015F53D87D97/image-size/medium?v=v2&amp;amp;px=400" role="button" title="validate_err.PNG" alt="validate_err.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 17:17:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217992#M41558</guid>
      <dc:creator>Checkper</dc:creator>
      <dc:date>2024-06-18T17:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 - NAT port forwarding with WAN DHCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217993#M41559</link>
      <description>&lt;P&gt;Seems that only dynamic_objects I've made my self is possible to list, no result when I try LocalMachine.&lt;/P&gt;&lt;P&gt;Another issue is policy push when LocalMachine is used in policy, requires target to be DAIP module.&amp;nbsp;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk180341" target="_blank" rel="noopener"&gt;sk180341&lt;/A&gt;&amp;nbsp;Same result if I specify target gateway.&lt;BR /&gt;Since Mgmt and Data plane isn't separated this is is maybe caused by static ip on Mgmt Interface and DHCP on External interface..?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Not sure what is best practice for this.. possible to separate it&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk138672" target="_self"&gt;sk138672 MDPS&lt;/A&gt;&amp;nbsp;but a lot of limits..&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 17:43:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/217993#M41559</guid>
      <dc:creator>Checkper</dc:creator>
      <dc:date>2024-06-18T17:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 - NAT port forwarding with WAN DHCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/218007#M41560</link>
      <description>&lt;P&gt;MDPS is not relevant for standalone systems.&lt;BR /&gt;Did you try enabling DAIP as described here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk166225" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk166225&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;I don't think you can enable it in SmartConsole since this is a standalone system, which I don't believe support DAIP.&lt;BR /&gt;However, this might enable updating of the LocalMachine object if you have one of your interfaces defined as dynamic.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 19:50:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/218007#M41560</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-18T19:50:58Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 - NAT port forwarding with WAN DHCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/218053#M41566</link>
      <description>&lt;P&gt;Tried to enable DAIP as described in sk166225, same result as&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk180341" target="_blank" rel="noopener"&gt;sk180341&lt;/A&gt;&amp;nbsp;afterwards.&lt;BR /&gt;Maybe DAIP not supported for standalone...&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2024 09:55:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/218053#M41566</guid>
      <dc:creator>Checkper</dc:creator>
      <dc:date>2024-06-19T09:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 - NAT port forwarding with WAN DHCP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/218250#M41631</link>
      <description>&lt;P&gt;The functionality to enable DAIP functionality is only supported on pure gateways (not standalone).&lt;BR /&gt;While a dynamic address will still work, you'll have to create and update your own Dynamic Object.&lt;BR /&gt;While you could script updating a dynamic_object, if you're using R81.20, you can do a Network Feed object that achieves the same thing.&lt;BR /&gt;Create the object as follows:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26372i03AB9E21CFCE3476/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Note that I have no idea how reliable ipify is as I just found it with a quick Internet search.&lt;BR /&gt;However, anything that returns your public IP either in ASCII (like &lt;A href="https://api.ipify.com" target="_blank" rel="noopener"&gt;https://api.ipify.com&lt;/A&gt;&amp;nbsp;does) or in JSON can be used.&lt;BR /&gt;Network Feed objects can be used in the Access Policy and NAT configuration on R81.20+ gateways.&lt;/P&gt;
&lt;P&gt;It should also be noted that locally managed Quantum Spark appliances support this use case much better (using Server objects).&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 14:54:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/3600-NAT-port-forwarding-with-WAN-DHCP/m-p/218250#M41631</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-20T14:54:13Z</dc:date>
    </item>
  </channel>
</rss>

