<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP pool Source NAT issue R82.10 L2TP + IPsec in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266586#M52688</link>
    <description>&lt;P&gt;I'm guessing this is related to the move to UPPAK, which you probably weren't running in the older environment.&lt;BR /&gt;TAC will definitely need to be involved.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jan 2026 15:32:27 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2026-01-06T15:32:27Z</dc:date>
    <item>
      <title>IP pool Source NAT issue R82.10 L2TP + IPsec</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266553#M52679</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Env:&lt;/P&gt;
&lt;P&gt;CP3950 clusterXL R82.10 jumbo take 22&lt;/P&gt;
&lt;P&gt;VM management server R82 jumbo take 44&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tested CP3950, and L2TP users cannot access internal resource when VPN connection established.&lt;/P&gt;
&lt;P&gt;I migrated all visible configuration from the actual environment, including database of management server, to two of CP3950, and VM management server.&lt;/P&gt;
&lt;P&gt;The original product environment provides wide range of availability with L2TP users, so I did not expect it failed on CP3950.&lt;/P&gt;
&lt;P&gt;All visible configuration such as GAiA configurations, and management server database are same as I double-checked, so I thought I might have missed some kernel parameters.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I noticed log says an unfamiliar IP address (10.127.45.X) for the connection of L2TP user while xxx.xxx.252.x/24 is expected.(IP Pool NAT)&lt;/P&gt;
&lt;P&gt;Therefore, I hit google, and found seemingly related sk (&lt;SPAN&gt;sk172805).&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk172805" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk172805&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am not certain if this is relevant or not...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any comments are more than welcome, but since the appliances are not within my reach log retrieving takes time.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Saitoh&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2026 01:35:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266553#M52679</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2026-01-08T01:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: IP pool Source NAT issue R82.10 L2TP + IPsec</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266555#M52680</link>
      <description>&lt;P&gt;I don't believe your issue matches this, if you've confirmed the office mode address range and NAT configuration please open an SR with TAC to investigate further.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2026 11:08:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266555#M52680</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-01-06T11:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: IP pool Source NAT issue R82.10 L2TP + IPsec</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266558#M52681</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Greetings to Japan and Happy New Year!&lt;/P&gt;
&lt;P&gt;I tend to agree with Chris, does not seem to me that sk would be 100% relevant in your specific case. Definitely best to open TAC case and let them confirm.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2026 11:53:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266558#M52681</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-06T11:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: IP pool Source NAT issue R82.10 L2TP + IPsec</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266586#M52688</link>
      <description>&lt;P&gt;I'm guessing this is related to the move to UPPAK, which you probably weren't running in the older environment.&lt;BR /&gt;TAC will definitely need to be involved.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2026 15:32:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266586#M52688</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-01-06T15:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: IP pool Source NAT issue R82.10 L2TP + IPsec</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266620#M52700</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thank you for the feedback.&lt;/P&gt;
&lt;P&gt;I asked to check your case in our lab, and indeed seems that there is a bug which cause this behavior.&lt;/P&gt;
&lt;P&gt;We are working to fix it and the fix will be included in one of the next JHF releases (#1 or #2).&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Idan Tsarfati&lt;/P&gt;
&lt;P&gt;R&amp;amp;D Director&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2026 20:30:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266620#M52700</guid>
      <dc:creator>idants</dc:creator>
      <dc:date>2026-01-06T20:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: IP pool Source NAT issue R82.10 L2TP + IPsec</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266732#M52724</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Much appreciated to your comments! It is fortune for me and the community that you legends are always here to help us &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and&amp;nbsp;thanks for conforming this behavior&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/32330"&gt;@idants&lt;/a&gt;!&lt;/P&gt;
&lt;P&gt;I will open an TAC case to ask them for a bit more details.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Saitoh&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2026 01:55:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266732#M52724</guid>
      <dc:creator>saitoh</dc:creator>
      <dc:date>2026-01-08T01:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: IP pool Source NAT issue R82.10 L2TP + IPsec</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266733#M52725</link>
      <description>&lt;P&gt;Im sure it will be fixed soon, as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/32330"&gt;@idants&lt;/a&gt;&amp;nbsp;indicated.&lt;/P&gt;
&lt;P&gt;日本へのご挨拶&lt;/P&gt;
&lt;P&gt;I hope google translate did that right : -)&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2026 02:28:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/IP-pool-Source-NAT-issue-R82-10-L2TP-IPsec/m-p/266733#M52725</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-08T02:28:25Z</dc:date>
    </item>
  </channel>
</rss>

