<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Manual DNAT rule is not working in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/239010#M46375</link>
    <description>&lt;P&gt;Can the client learn the arp, any drop logs?&lt;/P&gt;
&lt;P&gt;If this is VMware is it configured per&amp;nbsp;&lt;SPAN&gt;sk101214.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 19 Jan 2025 06:20:59 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2025-01-19T06:20:59Z</dc:date>
    <item>
      <title>Manual DNAT rule is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/238999#M46370</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;I have a standalone box on VM, I'm trying to create a DNAT rule for servers that are directly connected to CP box.&lt;/P&gt;&lt;P&gt;#################&lt;/P&gt;&lt;P&gt;Firewall interfaces :&lt;/P&gt;&lt;P&gt;10.10.10.101 -eth0&lt;/P&gt;&lt;P&gt;20.20.20.101- eth2&lt;/P&gt;&lt;P&gt;#################&lt;/P&gt;&lt;P&gt;I have servers behind each of these interfaces, I'm trying to create a DNAT for the web server manually, Below are the steps that I followed.&lt;/P&gt;&lt;P&gt;1&amp;gt;Created a DNAT rule.&lt;/P&gt;&lt;P&gt;2&amp;gt;Created a proxy ARP entry in WebUI.&lt;/P&gt;&lt;P&gt;3&amp;gt;Enabled manual proxy in global config.&lt;/P&gt;&lt;P&gt;4&amp;gt;Installed policy.&lt;/P&gt;&lt;P&gt;Web server 10.10.10.10&lt;/P&gt;&lt;P&gt;Client - 20.20.20.10&lt;/P&gt;&lt;P&gt;##############&lt;/P&gt;&lt;P&gt;Below is the proxy arp o/p from cli&lt;/P&gt;&lt;P&gt;[Expert@CheckPoint_SA:0]# fw ctl arp&lt;BR /&gt;&lt;STRONG&gt;(20.20.20.105) at 00-0c-29-12-90-66&lt;/STRONG&gt;&lt;BR /&gt;[Expert@CheckPoint_SA:0]# ifconfig eth2&lt;BR /&gt;eth2 Link encap:Ethernet HWaddr &lt;STRONG&gt;00:0C:29:12:90:66&lt;/STRONG&gt;&lt;BR /&gt;inet addr:20.20.20.101 Bcast:20.20.20.255 Mask:255.255.255.0&lt;BR /&gt;UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1&lt;BR /&gt;RX packets:2854 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;TX packets:180 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;collisions:0 txqueuelen:1000&lt;BR /&gt;RX bytes:265199 (258.9 KiB) TX bytes:10990 (10.7 KiB)&lt;/P&gt;&lt;P&gt;==========&lt;/P&gt;&lt;P&gt;I have attached screenshots for the NAT rule and the access rule .&lt;/P&gt;&lt;P&gt;Can someone please help me figure out what's happening here!&lt;/P&gt;&lt;P&gt;=========&lt;/P&gt;&lt;P&gt;WR,&lt;/P&gt;&lt;P&gt;FH&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jan 2025 18:30:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/238999#M46370</guid>
      <dc:creator>Firewall_Head</dc:creator>
      <dc:date>2025-01-18T18:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Manual DNAT rule is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/239004#M46372</link>
      <description>&lt;P&gt;Is Linux_2 the client and Linux_1 the server?&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2025 00:50:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/239004#M46372</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-01-19T00:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Manual DNAT rule is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/239009#M46374</link>
      <description>&lt;P&gt;Yes&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2025 04:44:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/239009#M46374</guid>
      <dc:creator>Firewall_Head</dc:creator>
      <dc:date>2025-01-19T04:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Manual DNAT rule is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/239010#M46375</link>
      <description>&lt;P&gt;Can the client learn the arp, any drop logs?&lt;/P&gt;
&lt;P&gt;If this is VMware is it configured per&amp;nbsp;&lt;SPAN&gt;sk101214.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2025 06:20:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/239010#M46375</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-01-19T06:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: Manual DNAT rule is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/239012#M46376</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;If you take a look at my proxy ARP output, the MAC of eth2 and the NAT IP are the same. Is this expected ?&lt;/P&gt;&lt;P&gt;Also I'm seeing drops for the traffic initiated to the NAT IP , it is matched by cleanup rule. I'm a little confused here, I have used the real IP in access control policy , can it be the reason.&lt;/P&gt;&lt;P&gt;=====&lt;/P&gt;&lt;P&gt;WR,&lt;/P&gt;&lt;P&gt;FH&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2025 05:44:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/239012#M46376</guid>
      <dc:creator>Firewall_Head</dc:creator>
      <dc:date>2025-01-19T05:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Manual DNAT rule is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/239013#M46377</link>
      <description>&lt;P&gt;The proxy-arp mac should match the interface mac from the same subnet.&lt;/P&gt;
&lt;P&gt;Yes the traffic must be accepted by the access policy (NAT IP).&lt;/P&gt;
&lt;P&gt;If you used NAT on the object itself elements of the policy may appear different by comparison.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2025 06:38:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/239013#M46377</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-01-19T06:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: Manual DNAT rule is not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/239014#M46378</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;, it's working now.&lt;/P&gt;&lt;P&gt;Have a great day!&lt;/P&gt;&lt;P&gt;=======&lt;/P&gt;&lt;P&gt;WR&lt;/P&gt;&lt;P&gt;FH&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jan 2025 06:40:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-DNAT-rule-is-not-working/m-p/239014#M46378</guid>
      <dc:creator>Firewall_Head</dc:creator>
      <dc:date>2025-01-19T06:40:50Z</dc:date>
    </item>
  </channel>
</rss>

