<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT on gateway itself for IKE traffic in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-on-gateway-itself-for-IKE-traffic/m-p/238917#M46342</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have a new service provider that we're connected to and their GW is 172.16.0.1/29, on their end they forward all the public network traffic (/28) to the Checkpoint VIP(172.16.0.2/29) and we perform all NAT on our end.&lt;/P&gt;&lt;P&gt;We have hide behind NAT configured on our network objects and that's all working great but the IKE traffic is generated by the gateway itself so it's not getting NAT translation so the provider sees the VIP address and can't route it.&lt;/P&gt;&lt;P&gt;Is there a way to NAT the Gateway itself so IKE appears as a NAT address instead of the 172.16.0.2/29 private interface VIP?&lt;/P&gt;&lt;P&gt;Any thoughts how this can be accomplished?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jan 2025 13:51:37 GMT</pubDate>
    <dc:creator>asaivephac</dc:creator>
    <dc:date>2025-01-17T13:51:37Z</dc:date>
    <item>
      <title>NAT on gateway itself for IKE traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-on-gateway-itself-for-IKE-traffic/m-p/238917#M46342</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have a new service provider that we're connected to and their GW is 172.16.0.1/29, on their end they forward all the public network traffic (/28) to the Checkpoint VIP(172.16.0.2/29) and we perform all NAT on our end.&lt;/P&gt;&lt;P&gt;We have hide behind NAT configured on our network objects and that's all working great but the IKE traffic is generated by the gateway itself so it's not getting NAT translation so the provider sees the VIP address and can't route it.&lt;/P&gt;&lt;P&gt;Is there a way to NAT the Gateway itself so IKE appears as a NAT address instead of the 172.16.0.2/29 private interface VIP?&lt;/P&gt;&lt;P&gt;Any thoughts how this can be accomplished?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 13:51:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-on-gateway-itself-for-IKE-traffic/m-p/238917#M46342</guid>
      <dc:creator>asaivephac</dc:creator>
      <dc:date>2025-01-17T13:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: NAT on gateway itself for IKE traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-on-gateway-itself-for-IKE-traffic/m-p/238924#M46344</link>
      <description>&lt;P&gt;Which device has a public IP-address?&lt;/P&gt;&lt;P&gt;NAT-T should take care of IKE with NAT.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 14:33:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-on-gateway-itself-for-IKE-traffic/m-p/238924#M46344</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2025-01-17T14:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: NAT on gateway itself for IKE traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-on-gateway-itself-for-IKE-traffic/m-p/238925#M46345</link>
      <description>&lt;P&gt;The provider FW has public IP-address and has a rule to forward everything to our VIP and we manage our own NAT translation.&lt;/P&gt;&lt;P&gt;If I were to put a manual NAT-t entry for (CP VIP) 172.16.10.2 &amp;gt; NAT, would the ipsec tunnel use the nat address? I'm not sure if Nat-T is before or after VPN.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 14:46:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-on-gateway-itself-for-IKE-traffic/m-p/238925#M46345</guid>
      <dc:creator>asaivephac</dc:creator>
      <dc:date>2025-01-17T14:46:43Z</dc:date>
    </item>
  </channel>
</rss>

