<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Additional NAT rule 0 in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Additional-NAT-rule-0/m-p/130074#M75111</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a related question regarding NAT Additional Rule Number.&lt;/P&gt;&lt;P&gt;We have a NAT rule that translated various internal subnets to a hide-NAT address.&lt;/P&gt;&lt;P&gt;The logs that hits this NAT rule correctly shows the NAT rule number (NAT rule #8 in our case), but it also shows a "NAT Additional Rule Number". For most entries it is 1, but for some entries it is 0.&lt;/P&gt;&lt;P&gt;Could someone explain what this means and the reason this is happening?&lt;/P&gt;&lt;P&gt;Please note that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;NAT rule #1 does not at all match the traffic for the log entries with this behavior&lt;/LI&gt;&lt;LI&gt;We do not have "Hide Internal networks behind gateway's external IP" enabled on the gateways&lt;/LI&gt;&lt;LI&gt;We do not have "Allow bi-directional NAT" enabled in the global properties&lt;/LI&gt;&lt;LI&gt;This is traffic from inside subnets, not addresses on the firewalls themselves&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;BR /&gt;We are running R80.40 on the MDS servers and R80.20 on the security gateways.&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;Harry&lt;/P&gt;</description>
    <pubDate>Thu, 23 Sep 2021 12:57:47 GMT</pubDate>
    <dc:creator>net-harry</dc:creator>
    <dc:date>2021-09-23T12:57:47Z</dc:date>
    <item>
      <title>Additional NAT rule 0</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Additional-NAT-rule-0/m-p/124980#M75109</link>
      <description>&lt;P&gt;Good morning,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a manual static NAT rule configured in our rulebase:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Original Source: x.x.x.x - Original Destination: y.y.y.y - Original Service: any - Translate Source: Original - Translate Destination: z.z.z.z - Translate Service: original&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The NAT rule itself works fine. In the logs, I can see the traffic is hitting the correct NAT rule (NAT rule 10, for example), but I can also see "NAT Additional Rule Number 0" in the logs. Initial research suggests that this is related to bi-directional NAT (which is enabled in Global Properties), but I thought this was only applied to automatic rules? Not manual? This is happening on the majority of our NAT rules, most of which are manual.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;R80.40, take 118.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone help clarify this, please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 07:35:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Additional-NAT-rule-0/m-p/124980#M75109</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2021-07-27T07:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Additional NAT rule 0</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Additional-NAT-rule-0/m-p/125037#M75110</link>
      <description>&lt;P&gt;I'm a bit hazy on this but NAT rule 0 applies in the following situations I can think of:&lt;/P&gt;
&lt;P&gt;1)&amp;nbsp;NAT "Hide Internal networks behind gateway's external IP" is set on the gateway/cluster object (not default setting)&lt;/P&gt;
&lt;P&gt;2) Certain traffic to and from cluster member themselves, including control traffic&lt;/P&gt;
&lt;P&gt;3) Traffic matching the implied Firewall policy rules (Actions...Display Implied Rules) from Security Policies tab in SmartConsole&lt;/P&gt;
&lt;P&gt;4) Possibly lack of inspection/handling due to Wire Mode&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 17:31:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Additional-NAT-rule-0/m-p/125037#M75110</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-07-27T17:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Additional NAT rule 0</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Additional-NAT-rule-0/m-p/130074#M75111</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a related question regarding NAT Additional Rule Number.&lt;/P&gt;&lt;P&gt;We have a NAT rule that translated various internal subnets to a hide-NAT address.&lt;/P&gt;&lt;P&gt;The logs that hits this NAT rule correctly shows the NAT rule number (NAT rule #8 in our case), but it also shows a "NAT Additional Rule Number". For most entries it is 1, but for some entries it is 0.&lt;/P&gt;&lt;P&gt;Could someone explain what this means and the reason this is happening?&lt;/P&gt;&lt;P&gt;Please note that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;NAT rule #1 does not at all match the traffic for the log entries with this behavior&lt;/LI&gt;&lt;LI&gt;We do not have "Hide Internal networks behind gateway's external IP" enabled on the gateways&lt;/LI&gt;&lt;LI&gt;We do not have "Allow bi-directional NAT" enabled in the global properties&lt;/LI&gt;&lt;LI&gt;This is traffic from inside subnets, not addresses on the firewalls themselves&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;BR /&gt;We are running R80.40 on the MDS servers and R80.20 on the security gateways.&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;Harry&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 12:57:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Additional-NAT-rule-0/m-p/130074#M75111</guid>
      <dc:creator>net-harry</dc:creator>
      <dc:date>2021-09-23T12:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: Additional NAT rule 0</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Additional-NAT-rule-0/m-p/130168#M75112</link>
      <description>&lt;P&gt;Normally the NAT additional rule number should be blank unless two automatic rules were matched (one for source and one for destination), but according to sk144192:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;When matching 2 automatic rules, second rule match will be shown otherwise NAT Additional Rule field will be 0.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;So that explains the NAT additional rule being 0 when matching only one automatic rule.&amp;nbsp; If a manual NAT rule is matched, only that one rule can be matched and the NAT additional rule should always be blank (or maybe 0).&amp;nbsp; Not sure why the field would show 1, perhaps it is trying to indicate that only one NAT rule (a manual one) is matched?&amp;nbsp; There were some changes to NAT made in R80.40 involving GNAT &amp;amp; exhaustion pools and such, perhaps this behavior change in the logs is related to that?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 12:31:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Additional-NAT-rule-0/m-p/130168#M75112</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-09-24T12:31:42Z</dc:date>
    </item>
  </channel>
</rss>

