<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBR and Source NAT in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218937#M41846</link>
    <description>&lt;P&gt;And why not use the PBR route based on the real ip instead of NAT pool range?&lt;/P&gt;</description>
    <pubDate>Thu, 27 Jun 2024 08:40:16 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2024-06-27T08:40:16Z</dc:date>
    <item>
      <title>PBR and Source NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218936#M41845</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;we have a Cluster running on R81.20 with JHF T65.&lt;/P&gt;&lt;P&gt;We want to separate WebEX from other traffic.&lt;/P&gt;&lt;P&gt;So I used the Updatable Object for allowing the Traffic to "WebEX Services".&lt;/P&gt;&lt;P&gt;In NAT-Rules I created a Source NAT:&lt;/P&gt;&lt;P&gt;internal Net --&amp;gt; WebEX Services&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NAT-IP 10.1.1.1 (hide)&amp;nbsp; ---&amp;gt; original&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rule and NAT is working fine, BUT ....&lt;/P&gt;&lt;P&gt;I have configured PBR to work for Source IP.&lt;/P&gt;&lt;P&gt;BPR-Rule:&amp;nbsp; &amp;nbsp;If Source IP is 10.1.1.1&amp;nbsp; &amp;nbsp;---&amp;gt;&amp;nbsp; &amp;nbsp;Route Destination x.x.x.14&lt;/P&gt;&lt;P&gt;Default Route is x.x.x.254 (Loadbalancer)&lt;/P&gt;&lt;P&gt;So I expected, that the traffic, which has been source natted to 10.1.1.1 will use the&lt;/P&gt;&lt;P&gt;PBR Route for x.x.x.14 and NOT my default Route to the loadbalancer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately it still uses the default route!&lt;/P&gt;&lt;P&gt;Is the order for PBR.....&amp;nbsp; &amp;nbsp;first look up for PBR and than make Source NAT ???&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 08:27:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218936#M41845</guid>
      <dc:creator>Axel_Winterberg</dc:creator>
      <dc:date>2024-06-27T08:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and Source NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218937#M41846</link>
      <description>&lt;P&gt;And why not use the PBR route based on the real ip instead of NAT pool range?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 08:40:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218937#M41846</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-06-27T08:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and Source NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218942#M41847</link>
      <description>&lt;P&gt;Because, that will match all traffic from the real IPs.&lt;BR /&gt;I do source NAT only for Destination WebEX Services.&lt;BR /&gt;So original Source with other Destination musst use default route.&lt;/P&gt;&lt;P&gt;Destination WebEX Services are Source natted and should use PBR Route&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 08:44:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218942#M41847</guid>
      <dc:creator>Axel_Winterberg</dc:creator>
      <dc:date>2024-06-27T08:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and Source NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218944#M41848</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk163320" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk163320&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 08:49:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218944#M41848</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-06-27T08:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and Source NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218945#M41849</link>
      <description>&lt;P&gt;Yes, i have seen it.&lt;/P&gt;&lt;P&gt;I will try another way to separate the traffic:&lt;/P&gt;&lt;H2&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Enabling Firewall rule matching in PBR (Application-Based Routing)&lt;/H2&gt;&lt;P&gt;The purpose of extending the basic PBR rule criteria to include Firewall rule is to enable users to match on configured Firewall rules and forward traffic accordingly. This extension of PBR functionality forwards the traffic based on application, service, users, time, location, and many more, as supported by FW rules.&lt;/P&gt;&lt;P&gt;Currently, this feature is supported to direct Office365 traffic to Microsoft Cloud and is being tested with other updatable SaaS and cloud service objects.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;This feature is currently hidden&lt;/STRONG&gt;. To enable it, run these commands on the Security Gateway in the Expert mode&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;and reboot&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;HostName:0# dbset process:rtgpbrd:runlevel 4&lt;/P&gt;&lt;P&gt;HostName:0# dbset process:rtgpbrd:path /bin&lt;/P&gt;&lt;P&gt;HostName:0# dbset process:rtgpbrd t&lt;/P&gt;&lt;P&gt;HostName:0# dbset :save&lt;/P&gt;&lt;P&gt;HostName:0# reboot&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 08:52:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218945#M41849</guid>
      <dc:creator>Axel_Winterberg</dc:creator>
      <dc:date>2024-06-27T08:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and Source NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218946#M41850</link>
      <description>&lt;P&gt;I will test this scenario, if I get a maintenance window from the customer.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 08:54:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218946#M41850</guid>
      <dc:creator>Axel_Winterberg</dc:creator>
      <dc:date>2024-06-27T08:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and Source NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218947#M41851</link>
      <description>&lt;P&gt;You mean then this SK correct?&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk167135" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk167135&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 08:54:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218947#M41851</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-06-27T08:54:47Z</dc:date>
    </item>
    <item>
      <title>Re: PBR and Source NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218949#M41852</link>
      <description>&lt;P&gt;Yes, have found sk167135.&lt;/P&gt;&lt;P&gt;Never tried this "hidden" feature. Will give it a try and will post my results.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2024 08:58:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-and-Source-NAT/m-p/218949#M41852</guid>
      <dc:creator>Axel_Winterberg</dc:creator>
      <dc:date>2024-06-27T08:58:09Z</dc:date>
    </item>
  </channel>
</rss>

