<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT with Multiple external interfaces in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-with-Multiple-external-interfaces/m-p/78356#M6027</link>
    <description>&lt;P&gt;The best way, in my opinion, to wait and see the BGP peer come up and the routes for it, then create a dynamic object or network group and the do the NAT-ing.&lt;/P&gt;</description>
    <pubDate>Sun, 15 Mar 2020 17:16:14 GMT</pubDate>
    <dc:creator>funkylicious</dc:creator>
    <dc:date>2020-03-15T17:16:14Z</dc:date>
    <item>
      <title>NAT with Multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-with-Multiple-external-interfaces/m-p/78215#M6005</link>
      <description>&lt;P&gt;I currently have CP 12600 firewall with an external interface to internet and internal interface. We have&amp;nbsp; NAT defined for all external flows. I want to create another external interface that will receive dynamic routes via BGP . I also want to assign a NAT pool to SNAT all flows sent via this interface. The challenge I have is how do I define this NAT when the destination ranges are dynamic and unknown ? My existing NAT from internal to external internet has 'any' for destination ranges which will overlap with any new NAT rules that can create.&amp;nbsp;&lt;BR /&gt;In summary,&lt;BR /&gt;a.how do I define NAT pool to SNAT all traffic send via the new interface ?&lt;BR /&gt;b. if there are overlapping NAT statements will CP check outgoing interface based on routing before deciding the NAT statement to use ? or will it process on the basis of order of NAT statements ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2020 14:11:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-with-Multiple-external-interfaces/m-p/78215#M6005</guid>
      <dc:creator>colfer</dc:creator>
      <dc:date>2020-03-13T14:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with Multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-with-Multiple-external-interfaces/m-p/78346#M6024</link>
      <description>&lt;P&gt;Well, do you want to use ECMP ( which should be enabled by default ) to load balance the traffic or just move all traffic to the new interface ?&lt;/P&gt;&lt;P&gt;If you want to move it to the new one, just change the nexthop for the default route and modify NAT table accordingly.&lt;/P&gt;&lt;P&gt;Otherwise, just add another default route with the nexthop and add another rule with dst any ( haven't tested, but should work ).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2020 14:18:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-with-Multiple-external-interfaces/m-p/78346#M6024</guid>
      <dc:creator>funkylicious</dc:creator>
      <dc:date>2020-03-15T14:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with Multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-with-Multiple-external-interfaces/m-p/78347#M6025</link>
      <description>&lt;P&gt;Hi -The current internet interface will be the one used by default;however, I want routes received via BGP on the new interface to be NAT’d using a separate pool of IP addresses. As I don’t know what these addresses are beforehand , how will I define the NAT?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2020 14:34:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-with-Multiple-external-interfaces/m-p/78347#M6025</guid>
      <dc:creator>colfer</dc:creator>
      <dc:date>2020-03-15T14:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with Multiple external interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-with-Multiple-external-interfaces/m-p/78356#M6027</link>
      <description>&lt;P&gt;The best way, in my opinion, to wait and see the BGP peer come up and the routes for it, then create a dynamic object or network group and the do the NAT-ing.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Mar 2020 17:16:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-with-Multiple-external-interfaces/m-p/78356#M6027</guid>
      <dc:creator>funkylicious</dc:creator>
      <dc:date>2020-03-15T17:16:14Z</dc:date>
    </item>
  </channel>
</rss>

