<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Internal Firewall Has No Internet Connection, But Network Within Internal LAN Has in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224781#M43212</link>
    <description>&lt;P&gt;Hello Checkmates,&lt;/P&gt;&lt;P&gt;I have a question regarding the behavior of my internal firewall. Please see image below as reference:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Simple1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27384i66BEA402E9801A31/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Simple1.png" alt="Simple1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Currently, anything below&amp;nbsp;&lt;STRONG&gt;INTFW&lt;/STRONG&gt; has internet access, but for some reason,&amp;nbsp;&lt;STRONG&gt;INTFW&amp;nbsp;&lt;/STRONG&gt;doesn't. I have confirmed this when I checked my URL and App Control updates, and it shows a failed attempt. Logs show allowed via implied rule as seen in the screenshot below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs1.png" style="width: 663px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27385i094ECB3C60DDE999/image-dimensions/663x252?v=v2" width="663" height="252" role="button" title="logs1.png" alt="logs1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Running&amp;nbsp;&lt;STRONG&gt;fwctl zdebug + drop | grep [INTFW IP] &lt;/STRONG&gt;on &lt;STRONG&gt;EXTFW1 &lt;/STRONG&gt;(current active cluster member)&amp;nbsp;doesn't show any drops, so it confirmed that the allowed log entries are correct. It shouldn't be about the routes as my internal network is working as it should be, it's only&amp;nbsp;&lt;STRONG&gt;INTFW&lt;/STRONG&gt; that doesn't have internet.&lt;BR /&gt;&lt;BR /&gt;I would like insight to this as it would allow me to then update my internal firewall to the latest JHF and would probably fix a lot of issues that I'm experience.&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 28 Aug 2024 10:18:16 GMT</pubDate>
    <dc:creator>SecurityNed</dc:creator>
    <dc:date>2024-08-28T10:18:16Z</dc:date>
    <item>
      <title>Internal Firewall Has No Internet Connection, But Network Within Internal LAN Has</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224781#M43212</link>
      <description>&lt;P&gt;Hello Checkmates,&lt;/P&gt;&lt;P&gt;I have a question regarding the behavior of my internal firewall. Please see image below as reference:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Simple1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27384i66BEA402E9801A31/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Simple1.png" alt="Simple1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Currently, anything below&amp;nbsp;&lt;STRONG&gt;INTFW&lt;/STRONG&gt; has internet access, but for some reason,&amp;nbsp;&lt;STRONG&gt;INTFW&amp;nbsp;&lt;/STRONG&gt;doesn't. I have confirmed this when I checked my URL and App Control updates, and it shows a failed attempt. Logs show allowed via implied rule as seen in the screenshot below:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs1.png" style="width: 663px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27385i094ECB3C60DDE999/image-dimensions/663x252?v=v2" width="663" height="252" role="button" title="logs1.png" alt="logs1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Running&amp;nbsp;&lt;STRONG&gt;fwctl zdebug + drop | grep [INTFW IP] &lt;/STRONG&gt;on &lt;STRONG&gt;EXTFW1 &lt;/STRONG&gt;(current active cluster member)&amp;nbsp;doesn't show any drops, so it confirmed that the allowed log entries are correct. It shouldn't be about the routes as my internal network is working as it should be, it's only&amp;nbsp;&lt;STRONG&gt;INTFW&lt;/STRONG&gt; that doesn't have internet.&lt;BR /&gt;&lt;BR /&gt;I would like insight to this as it would allow me to then update my internal firewall to the latest JHF and would probably fix a lot of issues that I'm experience.&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 10:18:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224781#M43212</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-08-28T10:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Firewall Has No Internet Connection, But Network Within Internal LAN Has</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224783#M43213</link>
      <description>&lt;P&gt;What do the logs say, does it show the traffic is being NAT'd at the Ext firewall??&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 10:30:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224783#M43213</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-08-28T10:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Firewall Has No Internet Connection, But Network Within Internal LAN Has</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224791#M43216</link>
      <description>&lt;P&gt;Here's an example of a log egress to 8.8.8.8 from the INTFW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nonat.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27386iD2018DEEB0ADFA83/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nonat.png" alt="nonat.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I see no translation entries, but we do have a NAT policy, the group &lt;FONT color="#000000"&gt;&lt;STRONG&gt;INTERNAL&amp;nbsp;&lt;/STRONG&gt;should have the 192.168.4.X IP address configured on the internal firewall.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 10:51:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224791#M43216</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-08-28T10:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Firewall Has No Internet Connection, But Network Within Internal LAN Has</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224793#M43218</link>
      <description>&lt;P&gt;The source address shown in the log is different to the subnet you mention so it may not be hitting your current NAT rules.&lt;/P&gt;
&lt;P&gt;Granted since it's not an RFC1918 it might be a moot point if the address is valid otherwise.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 10:58:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224793#M43218</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-08-28T10:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Firewall Has No Internet Connection, But Network Within Internal LAN Has</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224795#M43220</link>
      <description>&lt;P&gt;Would I still need NAT if the scenario is:&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;INTFW [20.20.0.4] &amp;lt;---&amp;gt; EXTFW1&lt;/STRONG&gt; &lt;STRONG&gt;[20.20.0.3]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;That IP is the link that is directly connected to the EXTFW1, so I would assume I don't need to NAT it as its directly connected.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 10:57:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224795#M43220</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-08-28T10:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Firewall Has No Internet Connection, But Network Within Internal LAN Has</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224797#M43221</link>
      <description>&lt;P&gt;If it's a public routeable address that is valid and belongs to your org then no...&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 11:00:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224797#M43221</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-08-28T11:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Firewall Has No Internet Connection, But Network Within Internal LAN Has</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224801#M43223</link>
      <description>&lt;P&gt;Yes, that's why the behavior is unusual. To add, I can ping to my DMZ-residing servers without issue, it's that one hop going to the internet that is not working for some reason. So, for ping tests:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;INTFW --&amp;gt; EXTFW1 Interface (20.20.0.3) = ok&lt;/LI&gt;&lt;LI&gt;INTFW --&amp;gt; DMZ IPs (172.16.X.X) = ok&lt;/LI&gt;&lt;LI&gt;INTFW --&amp;gt; Internet = log says its okay, but ping within the gateway fails&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 28 Aug 2024 11:05:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224801#M43223</guid>
      <dc:creator>SecurityNed</dc:creator>
      <dc:date>2024-08-28T11:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Firewall Has No Internet Connection, But Network Within Internal LAN Has</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224807#M43227</link>
      <description>&lt;P&gt;I've sent you a DM to check something related here regarding your choice of IP addresses.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 12:00:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224807#M43227</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-08-28T12:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Firewall Has No Internet Connection, But Network Within Internal LAN Has</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224834#M43232</link>
      <description>&lt;P&gt;If you run ip r g 8.8.8.8 command, what does it show?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 13:35:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224834#M43232</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-28T13:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Firewall Has No Internet Connection, But Network Within Internal LAN Has</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224837#M43234</link>
      <description>&lt;P&gt;Most likely the issue is the source IP in this case.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 13:44:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Internal-Firewall-Has-No-Internet-Connection-But-Network-Within/m-p/224837#M43234</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-08-28T13:44:05Z</dc:date>
    </item>
  </channel>
</rss>

