<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not Up, VPN site to site with NAT in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-Up-VPN-site-to-site-with-NAT/m-p/248464#M48532</link>
    <description>&lt;P&gt;8.png -&amp;gt; change from host to subnet. if this not works change to gateway. Both changes require policy push.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;topo i cannot read so cannot double check encryption domains / nat table. Also make sure disable nat option is disabled in the vpn community.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 May 2025 19:24:40 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2025-05-08T19:24:40Z</dc:date>
    <item>
      <title>Not Up, VPN site to site with NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-Up-VPN-site-to-site-with-NAT/m-p/248419#M48525</link>
      <description>&lt;P&gt;I have the vpn site to site between checkpoint and fortigate as below ( NAT only at checkpoint )&lt;/P&gt;&lt;P&gt;I have&amp;nbsp;referenced and configured&amp;nbsp; many guides but tunnel still does not work.&lt;/P&gt;&lt;P&gt;The log on the Fortigate reports that phase 2 is failing ( when no use NAT , everythings is good )&lt;/P&gt;&lt;P&gt;Pls, help me this issue ( nextime, we will swap ASA to checkpoint )&lt;/P&gt;&lt;P&gt;My device runs os 81.20&lt;/P&gt;&lt;P&gt;My configuration is as pictures below.&lt;/P&gt;&lt;P&gt;Thank,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 08:14:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-Up-VPN-site-to-site-with-NAT/m-p/248419#M48525</guid>
      <dc:creator>DaoSon</dc:creator>
      <dc:date>2025-05-08T08:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Not Up, VPN site to site with NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-Up-VPN-site-to-site-with-NAT/m-p/248447#M48530</link>
      <description>&lt;P&gt;It's far better to post screenshots inline in the editor rather than as attachments, FYI.&lt;/P&gt;
&lt;P&gt;The fact it works without NAT occurring on the Check Point side suggests the Fortigate isn't configured correctly to account for the NAT addresses.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 13:28:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-Up-VPN-site-to-site-with-NAT/m-p/248447#M48530</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-05-08T13:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: Not Up, VPN site to site with NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-Up-VPN-site-to-site-with-NAT/m-p/248464#M48532</link>
      <description>&lt;P&gt;8.png -&amp;gt; change from host to subnet. if this not works change to gateway. Both changes require policy push.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;topo i cannot read so cannot double check encryption domains / nat table. Also make sure disable nat option is disabled in the vpn community.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 19:24:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-Up-VPN-site-to-site-with-NAT/m-p/248464#M48532</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-05-08T19:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: Not Up, VPN site to site with NAT</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-Up-VPN-site-to-site-with-NAT/m-p/248476#M48538</link>
      <description>&lt;P&gt;Apart from what guys said, make sure below are set to FALSE on CP side from guidbedit.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;ike_enable_supernet&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;ike_p2_enable_supernet_from_R80.20&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;ike_use_largest_possible_subnets&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2025 02:17:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Not-Up-VPN-site-to-site-with-NAT/m-p/248476#M48538</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-05-09T02:17:25Z</dc:date>
    </item>
  </channel>
</rss>

