<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Proxy ARP on R80.20 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-R80-20/m-p/64738#M83590</link>
    <description>&lt;P&gt;Johan,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17364" target="_self"&gt;Maarten_Sjouw&lt;/A&gt;&amp;nbsp; mentioned. You don't need an interface on your gateway for these type of NAT.&lt;/P&gt;&lt;P&gt;You have to configure your (or your providers) upstream routers to route the external /23 subnet to your gateway.&lt;/P&gt;&lt;P&gt;And your NAT rule is simple with the internal /23 as original source and external /23 subnet as translated source.&lt;/P&gt;&lt;P&gt;If the packets routed through your gateway, there can be done NAT with these packets.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
    <pubDate>Thu, 10 Oct 2019 11:30:54 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2019-10-10T11:30:54Z</dc:date>
    <item>
      <title>Proxy ARP on R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-R80-20/m-p/64725#M83587</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have for sometime now been trying getting our Checkpoint Firewall to 1 to 1 NAT our VOIP phones.&lt;/P&gt;&lt;P&gt;What we just found out was that if we configure a 1 to 1 NAT rule like a /23 subnet to /23 subnet the firewall does not Proxy ARP the NAT subnet in case.&amp;nbsp;&lt;/P&gt;&lt;P&gt;A NAT rule with a /32 to /32 mask on it them will not work either.&lt;/P&gt;&lt;P&gt;However if we configure a 1 to 1 NAT rule wtih host objects like 1 host to 1 other host, the Proxy ARP works just fine.&lt;/P&gt;&lt;P&gt;This SK:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114395&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114395&amp;amp;partition=Advanced&amp;amp;product=Security&lt;/A&gt;&amp;nbsp;seems not aplicable on R80.20 since the variable of:&amp;nbsp;&lt;STRONG&gt;$CP_AUTO_ARP_FOR_MANUAL_NAT_RULES &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;is already "1"&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this a bug or what?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;//Johan&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2019 10:05:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-R80-20/m-p/64725#M83587</guid>
      <dc:creator>Johan_Rudberg</dc:creator>
      <dc:date>2019-10-10T10:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-R80-20/m-p/64731#M83588</link>
      <description>I would not use proxy ARP for a /23 at all, make sure that there is routing in place and don't make your gateway part of the /23 network.&lt;BR /&gt;Proxy ARP should only be needed and used when you have a smaller number of IP's that are on the external side of your gateway and you still want to use those addresses to forward traffic to some DMZ servers.</description>
      <pubDate>Thu, 10 Oct 2019 10:25:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-R80-20/m-p/64731#M83588</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-10-10T10:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-R80-20/m-p/64733#M83589</link>
      <description>&lt;P&gt;Then how would it work when it is described here in this guide:&amp;nbsp;CP_R80.20_VoIP_AdminGuide.pdf if Proxy ARP in larger networks, is not possible in a Checkpiont Firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Johan&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2019 10:36:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-R80-20/m-p/64733#M83589</guid>
      <dc:creator>Johan_Rudberg</dc:creator>
      <dc:date>2019-10-10T10:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on R80.20</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-R80-20/m-p/64738#M83590</link>
      <description>&lt;P&gt;Johan,&lt;/P&gt;&lt;P&gt;as&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17364" target="_self"&gt;Maarten_Sjouw&lt;/A&gt;&amp;nbsp; mentioned. You don't need an interface on your gateway for these type of NAT.&lt;/P&gt;&lt;P&gt;You have to configure your (or your providers) upstream routers to route the external /23 subnet to your gateway.&lt;/P&gt;&lt;P&gt;And your NAT rule is simple with the internal /23 as original source and external /23 subnet as translated source.&lt;/P&gt;&lt;P&gt;If the packets routed through your gateway, there can be done NAT with these packets.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2019 11:30:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-R80-20/m-p/64738#M83590</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-10-10T11:30:54Z</dc:date>
    </item>
  </channel>
</rss>

