<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX - NAT Configuration in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237030#M45962</link>
    <description>&lt;P&gt;Do you have screenshot of how rules are configured?&lt;/P&gt;</description>
    <pubDate>Sat, 28 Dec 2024 00:12:52 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-12-28T00:12:52Z</dc:date>
    <item>
      <title>VSX - NAT Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237026#M45960</link>
      <description>&lt;P&gt;Good morning,&amp;nbsp;&lt;/P&gt;&lt;P&gt;nice to meet you.&lt;/P&gt;&lt;P&gt;It's my first time I configured VSX, and with humility, I&amp;nbsp;&lt;SPAN&gt;I say I'm having problems configuring the NAT rules.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;AS you can see we deployed two VSs (one Internal and one External).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We would like to simplify as much as possible&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;the NAT rules.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For example, we tried to NAT management network (Static NAT rule) behind Public IP, but it does not work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Any suggestions about and how to configure NAT rules and where (which VS) in the easiest way to see less logs in the SmartDashboard are really appreciated (maybe with some examples).&lt;/P&gt;&lt;P&gt;Is there something wrong? I am really grateful to you.&lt;/P&gt;&lt;P&gt;Thanks, best regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 23:47:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237026#M45960</guid>
      <dc:creator>cp_lfr</dc:creator>
      <dc:date>2024-12-27T23:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - NAT Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237029#M45961</link>
      <description>&lt;P&gt;Just a quick suggestion:&lt;BR /&gt;&lt;BR /&gt;&amp;gt; we tried to NAT management network (Static NAT rule) behind Public IP, but it does not work.&lt;/P&gt;&lt;P&gt;This is your idea:&lt;/P&gt;&lt;P&gt;- Real SRC:&amp;nbsp; mgmt network&lt;BR /&gt;- Real DST: Any&lt;BR /&gt;- Translated Source:&amp;nbsp; the external IP of the firewall (so you configure a dynamic PAT, or "hidden", not "static")&lt;BR /&gt;- Translated DST: = (he same as the real DST)&lt;/P&gt;&lt;P&gt;You can use the "hide the traffic behind the external IP", but personally, I prefer an explicit manual NAT rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Dec 2024 23:52:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237029#M45961</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2024-12-27T23:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - NAT Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237030#M45962</link>
      <description>&lt;P&gt;Do you have screenshot of how rules are configured?&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 00:12:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237030#M45962</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-28T00:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - NAT Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237037#M45966</link>
      <description>&lt;P&gt;It was attached, and now it's deleted. The NAT rule on the screenshot was a static one from, for example, Net1 to Net1. Hence my note about PAT to the external iface.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 00:34:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237037#M45966</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2024-12-28T00:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - NAT Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237057#M45982</link>
      <description>&lt;P&gt;When using manual NAT, ensure that Proxy ARP is properly configured and that the "Merge manual proxy ARP configuration" option is selected in the Global Properties under NAT settings.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 05:34:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237057#M45982</guid>
      <dc:creator>Jarvis_Lin</dc:creator>
      <dc:date>2024-12-28T05:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - NAT Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237064#M45985</link>
      <description />
      <pubDate>Sat, 28 Dec 2024 13:31:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237064#M45985</guid>
      <dc:creator>cp_lfr</dc:creator>
      <dc:date>2024-12-28T13:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - NAT Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237065#M45986</link>
      <description>&lt;P&gt;Hello, so, I posted all screenshots!&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 13:32:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237065#M45986</guid>
      <dc:creator>cp_lfr</dc:creator>
      <dc:date>2024-12-28T13:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - NAT Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237066#M45987</link>
      <description>&lt;P&gt;Hello, as you can see I posted screenshots.&lt;/P&gt;&lt;P&gt;In case, which IP address do I need to use as a proxy ARP?&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 13:33:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237066#M45987</guid>
      <dc:creator>cp_lfr</dc:creator>
      <dc:date>2024-12-28T13:33:54Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - NAT Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237067#M45988</link>
      <description>&lt;P&gt;Hello, I posted all screenshots, but I am lost on this configuration&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;, any suggestion about configuration?&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 13:36:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237067#M45988</guid>
      <dc:creator>cp_lfr</dc:creator>
      <dc:date>2024-12-28T13:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - NAT Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237076#M45995</link>
      <description>&lt;P&gt;For outgoing PAT (to the external IP of the firewall/cluster) you do not need proxy ARP.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Dec 2024 23:44:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237076#M45995</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2024-12-28T23:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: VSX - NAT Configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237251#M46052</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;so, at the end, today I simply created an automatic NAT rule (Oject and then Nite, Hide Behing the Gateway).&lt;/P&gt;&lt;P&gt;There is NAT on External VSX (enabled NAT, Hide behind the Gateway).&lt;/P&gt;&lt;P&gt;I think at the moment is the best solution!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2024 21:52:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-NAT-Configuration/m-p/237251#M46052</guid>
      <dc:creator>cp_lfr</dc:creator>
      <dc:date>2024-12-30T21:52:01Z</dc:date>
    </item>
  </channel>
</rss>

