<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hide Internal Network - Interface Specific? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-Internal-Network-Interface-Specific/m-p/240459#M46643</link>
    <description>&lt;P&gt;Do you have Quantum SD-WAN enabled? or it's a locally managed Spark SD-WAN?&lt;/P&gt;
&lt;P&gt;in general, you could just make sure to do double NAT, so F5 will NAT on the CP interface IP as well.&lt;/P&gt;
&lt;P&gt;if you are using Quantum SD-WAN you can use our 'NAT Per ISP' feature on infinity portal setting 'Hide behind GW' per each ISP/Interface, and on the one you don't want NAT set it to 'According to Smart Console' and in Smart Console make sure you don't have NAT for this networks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Feb 2025 11:58:38 GMT</pubDate>
    <dc:creator>AmirArama</dc:creator>
    <dc:date>2025-02-05T11:58:38Z</dc:date>
    <item>
      <title>Hide Internal Network - Interface Specific?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-Internal-Network-Interface-Specific/m-p/240401#M46631</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;&lt;P&gt;So we have a situation with 4 different ISPs on this SD-WAN configuration. The issue is that the main link goes through an F5 box before hitting the internet, and the F5 does NAT. The other ISPs connect directly to our gateway.&lt;/P&gt;&lt;P&gt;The question is can we make the "HIDE INTERNAL NETWORK" function interface specific somehow, so that if traffic goes out WAN 1 it does not NAT but if goes out the other WAN links it does?&lt;/P&gt;&lt;P&gt;The only way I could think of doing this is leave HIDE INTERNAL NETWORK turned off at the gateway level and create specific NAT rules using specific ZONEs for each ISP.&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;Thanks in advanced,&lt;/P&gt;&lt;P&gt;RK&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 19:02:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-Internal-Network-Interface-Specific/m-p/240401#M46631</guid>
      <dc:creator>RKinsp</dc:creator>
      <dc:date>2025-02-04T19:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Hide Internal Network - Interface Specific?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-Internal-Network-Interface-Specific/m-p/240417#M46632</link>
      <description>&lt;P&gt;The option you gave is pretty much how I would do it. Otherwise, that setting to hide internal networks is not interface specific, Im positive of that.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 20:52:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-Internal-Network-Interface-Specific/m-p/240417#M46632</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-04T20:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: Hide Internal Network - Interface Specific?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-Internal-Network-Interface-Specific/m-p/240422#M46634</link>
      <description>&lt;P&gt;Here is a good example. I know its R82 lab, but works the same even in R81.xx.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Feb 2025 22:03:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-Internal-Network-Interface-Specific/m-p/240422#M46634</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-04T22:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: Hide Internal Network - Interface Specific?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-Internal-Network-Interface-Specific/m-p/240459#M46643</link>
      <description>&lt;P&gt;Do you have Quantum SD-WAN enabled? or it's a locally managed Spark SD-WAN?&lt;/P&gt;
&lt;P&gt;in general, you could just make sure to do double NAT, so F5 will NAT on the CP interface IP as well.&lt;/P&gt;
&lt;P&gt;if you are using Quantum SD-WAN you can use our 'NAT Per ISP' feature on infinity portal setting 'Hide behind GW' per each ISP/Interface, and on the one you don't want NAT set it to 'According to Smart Console' and in Smart Console make sure you don't have NAT for this networks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Feb 2025 11:58:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-Internal-Network-Interface-Specific/m-p/240459#M46643</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2025-02-05T11:58:38Z</dc:date>
    </item>
  </channel>
</rss>

