<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP address used on partner network in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-address-used-on-partner-network/m-p/227898#M43820</link>
    <description>&lt;P&gt;There is a feature that we call NAT pools that will help with this if I understand your requirements.&lt;/P&gt;
&lt;P&gt;The remainder is standard BGP and NAT config, please review the above and advise which part if any you are stuck with from there?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_Advanced_Routing_AdminGuide/Topics-GARG/NAT-Pools.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_Advanced_Routing_AdminGuide/Topics-GARG/NAT-Pools.htm&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Sep 2024 13:19:32 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2024-09-25T13:19:32Z</dc:date>
    <item>
      <title>BGP address used on partner network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-address-used-on-partner-network/m-p/227893#M43819</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;We have some question about BGP and the (HideNAT ?)&amp;nbsp; address we are using when we access the network behind the BGP routers of the partner.&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;We have a BGP configuration. we have Datacen&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ter A and Datacenter B. In&amp;nbsp;Datacetnter A we have one checkpoint cluster node. In Datacenter B we have one checkpoint cluster node. In both datacenters we have a BGP router from an external partner. Two checkpoint interfaces and two BGP peer interfaces are in samen vlan. vlans are all transported over sitelink interconnect The two checkpoint interfaces used for the BGP are having a cluster address. This address is used in a hide nat rule so we access the partner network with this address. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;The partner wants us to use a diferent address then the cluster address and a address that is not directly attached to the cluster. We are ordered not to use any address that is used to setup the BGP sessions. We need to advertise this address to the partner so BGP knows where the traffic needs to be delivered. Can someone please have a look at the visio we dont know how we can use the given network address to acces the partners network. Normally we use the cluster address for this but as we now learned BGP need a diferent configuration. I hope someone can help us out.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;P&gt;&lt;SPAN class=""&gt;I now notice that the question could be made some more clear bij adding this comment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;What we want to achieve is that we use 10.20.50.14/31 as the source when we access the partner network behind the BGP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;We want to advertise 10.20.50.14/31 to the partner so that it knows this route leads to our environment.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;We are now using 10.20.30.51 in a hide nat rule, this is working, but not desired because it can break the BGP. How its done now works because the routers are on the same subnet and use arp and not the BGP route i advertise... &lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 12:56:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-address-used-on-partner-network/m-p/227893#M43819</guid>
      <dc:creator>Lars_de_Mooy</dc:creator>
      <dc:date>2024-09-25T12:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: BGP address used on partner network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-address-used-on-partner-network/m-p/227898#M43820</link>
      <description>&lt;P&gt;There is a feature that we call NAT pools that will help with this if I understand your requirements.&lt;/P&gt;
&lt;P&gt;The remainder is standard BGP and NAT config, please review the above and advise which part if any you are stuck with from there?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_Advanced_Routing_AdminGuide/Topics-GARG/NAT-Pools.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_Advanced_Routing_AdminGuide/Topics-GARG/NAT-Pools.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 13:19:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-address-used-on-partner-network/m-p/227898#M43820</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-09-25T13:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: BGP address used on partner network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-address-used-on-partner-network/m-p/227907#M43823</link>
      <description>&lt;P&gt;Hi Chris, thanks i think this could be what i need.&lt;/P&gt;&lt;P&gt;Can you please advice on what to do next, i assume i need to do this on both members;&lt;/P&gt;&lt;P&gt;Create the natpool on both members 10.20.50.14/31.&lt;/P&gt;&lt;P&gt;Then advanced routing -&amp;gt; route redistribution -&amp;gt; add redistribution from "nat pool" in the to protocol field "BGP AS AS4200030961"&lt;/P&gt;&lt;P&gt;and Then advanced routing -&amp;gt; route redistribution -&amp;gt; add redistribution from "nat pool" in the to protocol field "BGP AS AS4200030962"&lt;/P&gt;&lt;P&gt;this is how i advertise my natpool to the bgp peers ?&lt;/P&gt;&lt;P&gt;I dont understand how the traffic from the partner knows what to do with the traffic sended to the natpool.&lt;/P&gt;&lt;P&gt;This traffic is not part of any of the interfaces ?&lt;/P&gt;&lt;P&gt;Do i still need a hide nat rule and hide my outbound traffic behind the natpool address ?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 13:48:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-address-used-on-partner-network/m-p/227907#M43823</guid>
      <dc:creator>Lars_de_Mooy</dc:creator>
      <dc:date>2024-09-25T13:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: BGP address used on partner network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-address-used-on-partner-network/m-p/227908#M43824</link>
      <description>&lt;P&gt;Yes you still need NAT rules for the address you want the traffic to appear from.&lt;/P&gt;
&lt;P&gt;The NAT pool itself simply provides a mechanism to have these addresses participate in routing protocol advertisements.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 13:57:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-address-used-on-partner-network/m-p/227908#M43824</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-09-25T13:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: BGP address used on partner network</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-address-used-on-partner-network/m-p/228129#M43887</link>
      <description>&lt;P&gt;Hi all is working now, except for one small issue.&lt;/P&gt;&lt;P&gt;The juniper routers that we have the BGP sessions with are not updating the MAC addresses quick enough on cluster failover.&lt;/P&gt;&lt;P&gt;Is there any way to use a VMAC only on only one interface or something like that ?&lt;/P&gt;&lt;P&gt;I see the option in my cluster to enable VMAC but i am a bit worried to use this option and it may cause network outage because my whole cluster uses a VMAC all of a sudden ....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope to hear back from you thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Sep 2024 16:55:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-address-used-on-partner-network/m-p/228129#M43887</guid>
      <dc:creator>Lars_de_Mooy</dc:creator>
      <dc:date>2024-09-26T16:55:35Z</dc:date>
    </item>
  </channel>
</rss>

