<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Manual NAT rule with service translation, not translating service in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244874#M47655</link>
    <description>&lt;P&gt;Can you share a depersonalized screenshot of the ACL, which allows the inbound and outbound traffic?&lt;/P&gt;
&lt;P&gt;Maybe for easier understandig: if you set an automatic NAT for SMTP-&amp;gt; then check the rules that are created (NAT rulebase) -&amp;gt; you will get a impression how should look like the NAT for only SMTP&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30032iE8F87A640BB42A36/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30031i8B4D04A9E942C60B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Then you will be able to copy it and expand the rules with ports etc.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Mar 2025 16:07:17 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2025-03-26T16:07:17Z</dc:date>
    <item>
      <title>Manual NAT rule with service translation, not translating service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244314#M47544</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I'm having some troubles with using manual NAT rules to translate a service. I do have manual arp entries added and the merge arp enabled.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="natrules.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29961i6D84554605F3B793/image-size/large?v=v2&amp;amp;px=999" role="button" title="natrules.png" alt="natrules.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;From testing and from some packet captures, I can see that when traffic is destined for ms-mail2 it is natting to the correct IP, however the service isn't being translated from smtp(port 25) to smtp-alt(port 465).&lt;/P&gt;&lt;P&gt;This is my first venture down the manual NAT rules and I feel like I am missing something small.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Basically, wanting to do this. When port 25 traffic comes in on 66.66.66.1 it NATs to 10.10.10.11 and stays port 25, When port 25 traffic comes in on 66.66.66.2 it NATs to 10.10.10.11 and translates to port 465.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="email.png" style="width: 622px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29966iB0F928D3A8116970/image-size/large?v=v2&amp;amp;px=999" role="button" title="email.png" alt="email.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone please provide some guidance?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: to add more description&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2025 14:08:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244314#M47544</guid>
      <dc:creator>Sam_Ponder</dc:creator>
      <dc:date>2025-03-20T14:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT rule with service translation, not translating service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244738#M47636</link>
      <description>&lt;P&gt;Does the traffic hit the correct NAT rule? How does the traffic log look like?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe fwmonitor capture will give a hint&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;# fw monitor -e "host(x.x.x.x),accept;" -o outputfile.cap&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;in order to filter for inbound and outbound traffic related to host x.x.x.x.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Mar 2025 20:21:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244738#M47636</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-03-25T20:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT rule with service translation, not translating service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244811#M47644</link>
      <description>&lt;P&gt;I hope, I understood correctly:&lt;/P&gt;
&lt;P&gt;My guess are:&lt;/P&gt;
&lt;P&gt;ORIGINAL DST: 66.66.66.1&lt;BR /&gt;ORIGINAL Services: smtp&lt;BR /&gt;translates src: orginal&lt;BR /&gt;translated dst: 10.10.10.11&lt;/P&gt;
&lt;P&gt;ORIGINAL DST: 66.66.66.2&lt;BR /&gt;ORIGINAL Services: smtp&lt;BR /&gt;translates src: orginal&lt;BR /&gt;translated dst: 10.10.10.11&lt;BR /&gt;translated service: 465&lt;/P&gt;
&lt;P&gt;Have a try.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 12:02:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244811#M47644</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-03-26T12:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT rule with service translation, not translating service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244861#M47649</link>
      <description>&lt;P&gt;Hi Akos,&lt;/P&gt;&lt;P&gt;Yes, that is what I am using, well that and the reverse for outbound translation.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 14:53:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244861#M47649</guid>
      <dc:creator>Sam_Ponder</dc:creator>
      <dc:date>2025-03-26T14:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT rule with service translation, not translating service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244868#M47651</link>
      <description>&lt;P&gt;Ok. Do you have any hits on the rules?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 15:44:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244868#M47651</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-03-26T15:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT rule with service translation, not translating service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244870#M47653</link>
      <description>&lt;P&gt;Hi Lesley,&lt;/P&gt;&lt;P&gt;The capture shows it translating the address but not translating the service/port.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 15:50:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244870#M47653</guid>
      <dc:creator>Sam_Ponder</dc:creator>
      <dc:date>2025-03-26T15:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT rule with service translation, not translating service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244871#M47654</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no hits on the outbound nat rule, inbound nat rule shows a few, but it isnt translating the port/service. The firewall rule has hits on it, though it show nat 0 as the matching nat rule, in smartconsole logs. This is a clustered pair of 5400s.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit for clarification.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 15:54:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244871#M47654</guid>
      <dc:creator>Sam_Ponder</dc:creator>
      <dc:date>2025-03-26T15:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT rule with service translation, not translating service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244874#M47655</link>
      <description>&lt;P&gt;Can you share a depersonalized screenshot of the ACL, which allows the inbound and outbound traffic?&lt;/P&gt;
&lt;P&gt;Maybe for easier understandig: if you set an automatic NAT for SMTP-&amp;gt; then check the rules that are created (NAT rulebase) -&amp;gt; you will get a impression how should look like the NAT for only SMTP&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30032iE8F87A640BB42A36/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30031i8B4D04A9E942C60B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Then you will be able to copy it and expand the rules with ports etc.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 16:07:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244874#M47655</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-03-26T16:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT rule with service translation, not translating service</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244902#M47670</link>
      <description>&lt;P&gt;Akos,&lt;/P&gt;&lt;P&gt;Here you go. I want to add. Since initially starting this thread, I have it working on the firewall at our DR location. Initially, I got it working in Vegas by recreating the network objects that were in use and then it started working.&lt;/P&gt;&lt;P&gt;The IndyFW cluster, isn't behaving the same.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="acl-nat.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30034iC6EDED9FEC334233/image-size/large?v=v2&amp;amp;px=999" role="button" title="acl-nat.png" alt="acl-nat.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Edit: I am leaving on PTO today, returning on Monday&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 19:08:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-rule-with-service-translation-not-translating-service/m-p/244902#M47670</guid>
      <dc:creator>Sam_Ponder</dc:creator>
      <dc:date>2025-03-26T19:08:57Z</dc:date>
    </item>
  </channel>
</rss>

