<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Optimize NAT : merge two gateway into a new third one in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Optimize-NAT-merge-two-gateway-into-a-new-third-one/m-p/231406#M44600</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;I have this situation&lt;/P&gt;&lt;P&gt;Two cluster ,but thread them as GW , GW-A on Domain A and GW-B on Domain B ( I have a multi domain environment )&lt;BR /&gt;There is a lot of traffic between public network managed by each one and also FROM INTERNET.&lt;/P&gt;&lt;P&gt;GW A on Domain A&lt;/P&gt;&lt;P&gt;I have a lot of traffic &lt;STRONG&gt;to&lt;/STRONG&gt; network managed by GW B that match this nat hide done on GW A&lt;/P&gt;&lt;P&gt;SRC ANY&lt;BR /&gt;DST ANY ( it means only public destination,over internet )&lt;BR /&gt;SERVICE ANY&lt;BR /&gt;&lt;BR /&gt;SRCxlate PublicIP-Network-A&lt;BR /&gt;DSTxlate Original&lt;BR /&gt;SERVICExlate Original&lt;/P&gt;&lt;P&gt;(basically a simple nat hide behind a public ip )&lt;BR /&gt;&lt;BR /&gt;When the packet comes to GW B ,on Domain B ,it match this basic *destination static nat*&lt;/P&gt;&lt;P&gt;SRC ANY&lt;BR /&gt;DST&amp;nbsp;PublicIP-Network-B&lt;BR /&gt;SERVICE https&lt;/P&gt;&lt;P&gt;SRCxlate Original&lt;BR /&gt;DSTlate&amp;nbsp;PrivateIP-Network-B&lt;BR /&gt;SERVICExlate Original&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i'll merge this two gateway on GW C I need both the NAT above&amp;nbsp; for the traffic to and from Internet and a third one like for the traffic that is generated and directed to public network managed by GW C&lt;BR /&gt;&lt;BR /&gt;SRC ANY&lt;BR /&gt;DST&amp;nbsp;PublicIP-Network-B&lt;BR /&gt;SERVICE https&lt;BR /&gt;SRCxlate&amp;nbsp;PublicIP-Network-A&lt;BR /&gt;DSTxlate&amp;nbsp;PrivateIP-Network-B&lt;BR /&gt;SERVICExlate https&lt;BR /&gt;&lt;BR /&gt;Because its seems from my test that Checkpoint is not able to match two different nat rule.&lt;BR /&gt;This is a tested "workaround" and work,but during the merging of the policy and nat i'll to configure A LOT ( hundreds...) of manual nat like the last one because we have a huge number of public network that do this kinf of traffic between sites.&lt;BR /&gt;&lt;BR /&gt;Is there any smart way to do it ?&lt;/P&gt;</description>
    <pubDate>Thu, 31 Oct 2024 15:55:09 GMT</pubDate>
    <dc:creator>AleLovaz82</dc:creator>
    <dc:date>2024-10-31T15:55:09Z</dc:date>
    <item>
      <title>Optimize NAT : merge two gateway into a new third one</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Optimize-NAT-merge-two-gateway-into-a-new-third-one/m-p/231406#M44600</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;I have this situation&lt;/P&gt;&lt;P&gt;Two cluster ,but thread them as GW , GW-A on Domain A and GW-B on Domain B ( I have a multi domain environment )&lt;BR /&gt;There is a lot of traffic between public network managed by each one and also FROM INTERNET.&lt;/P&gt;&lt;P&gt;GW A on Domain A&lt;/P&gt;&lt;P&gt;I have a lot of traffic &lt;STRONG&gt;to&lt;/STRONG&gt; network managed by GW B that match this nat hide done on GW A&lt;/P&gt;&lt;P&gt;SRC ANY&lt;BR /&gt;DST ANY ( it means only public destination,over internet )&lt;BR /&gt;SERVICE ANY&lt;BR /&gt;&lt;BR /&gt;SRCxlate PublicIP-Network-A&lt;BR /&gt;DSTxlate Original&lt;BR /&gt;SERVICExlate Original&lt;/P&gt;&lt;P&gt;(basically a simple nat hide behind a public ip )&lt;BR /&gt;&lt;BR /&gt;When the packet comes to GW B ,on Domain B ,it match this basic *destination static nat*&lt;/P&gt;&lt;P&gt;SRC ANY&lt;BR /&gt;DST&amp;nbsp;PublicIP-Network-B&lt;BR /&gt;SERVICE https&lt;/P&gt;&lt;P&gt;SRCxlate Original&lt;BR /&gt;DSTlate&amp;nbsp;PrivateIP-Network-B&lt;BR /&gt;SERVICExlate Original&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i'll merge this two gateway on GW C I need both the NAT above&amp;nbsp; for the traffic to and from Internet and a third one like for the traffic that is generated and directed to public network managed by GW C&lt;BR /&gt;&lt;BR /&gt;SRC ANY&lt;BR /&gt;DST&amp;nbsp;PublicIP-Network-B&lt;BR /&gt;SERVICE https&lt;BR /&gt;SRCxlate&amp;nbsp;PublicIP-Network-A&lt;BR /&gt;DSTxlate&amp;nbsp;PrivateIP-Network-B&lt;BR /&gt;SERVICExlate https&lt;BR /&gt;&lt;BR /&gt;Because its seems from my test that Checkpoint is not able to match two different nat rule.&lt;BR /&gt;This is a tested "workaround" and work,but during the merging of the policy and nat i'll to configure A LOT ( hundreds...) of manual nat like the last one because we have a huge number of public network that do this kinf of traffic between sites.&lt;BR /&gt;&lt;BR /&gt;Is there any smart way to do it ?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 15:55:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Optimize-NAT-merge-two-gateway-into-a-new-third-one/m-p/231406#M44600</guid>
      <dc:creator>AleLovaz82</dc:creator>
      <dc:date>2024-10-31T15:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: Optimize NAT : merge two gateway into a new third one</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Optimize-NAT-merge-two-gateway-into-a-new-third-one/m-p/231494#M44622</link>
      <description>&lt;P&gt;Correct, only one NAT rule is matched per connection.&lt;BR /&gt;Which means you'll have to adjust your rules according to the new configuration.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Nov 2024 14:59:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Optimize-NAT-merge-two-gateway-into-a-new-third-one/m-p/231494#M44622</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-01T14:59:10Z</dc:date>
    </item>
  </channel>
</rss>

