<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hide NAT of the FW external IP in VSX configuration in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78981#M9227</link>
    <description>&lt;P&gt;Yes, a test host works well. Please see the example below (&lt;STRONG&gt;before and after the NAT&lt;/STRONG&gt; )&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="test_host.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4934iD5490D61E569F307/image-size/large?v=v2&amp;amp;px=999" role="button" title="test_host.png" alt="test_host.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 20 Mar 2020 13:31:48 GMT</pubDate>
    <dc:creator>redcrow</dc:creator>
    <dc:date>2020-03-20T13:31:48Z</dc:date>
    <item>
      <title>Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78943#M9221</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;is auto hide NAT possible for the FW IP (external interface of course) in VSX configuration?&lt;/P&gt;&lt;P&gt;Specifically, we have an Edge Firewall (Virtual System) with two interfaces (internal and external). Both interfaces are directly connected to a border router (Cisco 6800).&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@lntfw-pgtw2:4]# route -n&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Kernel IP routing table&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Destination Gateway Genmask Flags Metric Ref Use Iface&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;192.168.196.0 0.0.0.0 255.255.255.240 U 0 0 0 bond2.997&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;192.168.196.16 0.0.0.0 255.255.255.240 U 0 0 0 bond2.998&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.100.98.0 0.0.0.0 255.255.255.0 UD 0 0 0 bond2.998&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10.100.97.0 0.0.0.0 255.255.255.0 UD 0 0 0 bond2.997&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;x.x.0.0 10.100.97.1 255.255.0.0 UGD 0 0 0 bond2.997&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;0.0.0.0 10.100.98.1 0.0.0.0 UGD 0 0 0 bond2.998&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Since the external interface has a private IP (10.100.98.101), the VS can't go to the Internet. So, I'd like to add a hide NAT (with one of our public IPs) to the 10.100.98.101 IP address. I already tried these two methods:&lt;/P&gt;&lt;P&gt;- Created an object with IP 10.100.98.101 and set the option "NAT --&amp;gt; Add automatic address translation rules --&amp;gt; Hide behind IP address" (with public IP).&lt;/P&gt;&lt;P&gt;- Created an object with IP 10.100.98.101 (let's call it Priv) and another object with public IP (let's call Pub). Then I added the object Priv in "Original Source" and the object Pub in "Translated Source".&lt;/P&gt;&lt;P&gt;Unfortunately, I didn't have success... both methods didn't work. Tcpdump shows always 10.100.98.101 as source if I try to ping or telnet some destination. So, since I read &lt;A href="https://community.checkpoint.com/t5/General-Topics/NAT-process-for-self-originated-traffic/td-p/23677" target="_self"&gt;here&lt;/A&gt; this mechanism is feasible, I'm worndering if that is the same in VSX environments...&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Francesco&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 08:23:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78943#M9221</guid>
      <dc:creator>redcrow</dc:creator>
      <dc:date>2020-03-20T08:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78945#M9222</link>
      <description>&lt;P&gt;I would just create a NAT rule that has a group with all the addresses/nets you want to hide-nat as original source. Original destination would be any. Translated source would then be an object with your selected public address with method Hide. Place it at below all you other more specific NAT-rules.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 09:16:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78945#M9222</guid>
      <dc:creator>ias_gc-dk</dc:creator>
      <dc:date>2020-03-20T09:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78960#M9223</link>
      <description>&lt;P&gt;That was exactly the second method I tried. Please see the following images (tried again towards a single Public IP&amp;nbsp; as destination for a test):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nat_rule.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4927iEAD3BA247A6A8749/image-size/large?v=v2&amp;amp;px=999" role="button" title="nat_rule.png" alt="nat_rule.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tcpdump.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4928iA336A7D0DBD28692/image-size/large?v=v2&amp;amp;px=999" role="button" title="tcpdump.png" alt="tcpdump.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The object FW-Frontiera_10.100.98.101-External is a host containing the private IP 10.100.98.101 of the external interface.&lt;/LI&gt;&lt;LI&gt;The object Public_IP_Test is just a public IP to test the NAT (162.241.216.197)&lt;/LI&gt;&lt;LI&gt;The object FW-Frontiera_NAT-External is a host containing one of our enterprise Public IPs&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;As you can see, the source IP remains 10.100.98.101...&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 11:36:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78960#M9223</guid>
      <dc:creator>redcrow</dc:creator>
      <dc:date>2020-03-20T11:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78964#M9224</link>
      <description>&lt;P&gt;What if you tried with the VS-object for Original Source, instead of an object containing just the external ip?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 11:42:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78964#M9224</guid>
      <dc:creator>ias_gc-dk</dc:creator>
      <dc:date>2020-03-20T11:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78967#M9225</link>
      <description>&lt;P&gt;Already tried:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nat_rule.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4929i92DB390D8BEDA2AE/image-size/large?v=v2&amp;amp;px=999" role="button" title="nat_rule.png" alt="nat_rule.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;but...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="error.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4930iCD58A2A21E6D91BD/image-size/large?v=v2&amp;amp;px=999" role="button" title="error.png" alt="error.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Gateway: lntfw-pVSX1_Frontiera&lt;BR /&gt;Policy: Frontiera&lt;BR /&gt;Status: Failed&lt;BR /&gt;- Invalid Object 'lntfw-pVSX1_Frontiera' in Original Source of Address Translation Rule 1. The valid objects are: host, gateway, network, address range and router.&lt;BR /&gt;- Policy verification failed.&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 11:54:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78967#M9225</guid>
      <dc:creator>redcrow</dc:creator>
      <dc:date>2020-03-20T11:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78975#M9226</link>
      <description>&lt;P&gt;hmm.. never had to do NAT for traffic from the firewall itself, so I have not run into this before. Is this how it is supposed to be in production?&lt;/P&gt;&lt;P&gt;Don't you have a host behind the firewall you can test from?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 12:45:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78975#M9226</guid>
      <dc:creator>ias_gc-dk</dc:creator>
      <dc:date>2020-03-20T12:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78981#M9227</link>
      <description>&lt;P&gt;Yes, a test host works well. Please see the example below (&lt;STRONG&gt;before and after the NAT&lt;/STRONG&gt; )&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="test_host.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4934iD5490D61E569F307/image-size/large?v=v2&amp;amp;px=999" role="button" title="test_host.png" alt="test_host.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 13:31:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/78981#M9227</guid>
      <dc:creator>redcrow</dc:creator>
      <dc:date>2020-03-20T13:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79238#M9228</link>
      <description>&lt;P&gt;Any other ideas?&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Francesco&lt;/P&gt;</description>
      <pubDate>Sun, 22 Mar 2020 18:17:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79238#M9228</guid>
      <dc:creator>redcrow</dc:creator>
      <dc:date>2020-03-22T18:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79249#M9229</link>
      <description>What I'm missing here is the version you are running. Your second methos should work just fine, should not matter if it is VSX or not. What you should check though, after installing the policy, is if the NAT is showing a proxy arp for the IP by issueing in the VS context: fw ctl arp&lt;BR /&gt;Another small thingy, double check the Install on column, it shows a name there...&lt;BR /&gt;</description>
      <pubDate>Sun, 22 Mar 2020 21:42:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79249#M9229</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-22T21:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79277#M9230</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Just a dumb question but, is there an ACL for the traffic to be permitted ? I mean the 443 traffic and not the ICMP.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 06:11:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79277#M9230</guid>
      <dc:creator>funkylicious</dc:creator>
      <dc:date>2020-03-23T06:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79297#M9231</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17364"&gt;@Maarten_Sjouw&lt;/a&gt;: the VSX/Gateway version is 80.20, while the Server Management is running version 80.30.&lt;/P&gt;&lt;P&gt;After the installation, the command outputs "No Proxy ARP entries"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tcpdump.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5014i9D8482BFF184C50D/image-size/large?v=v2&amp;amp;px=999" role="button" title="tcpdump.png" alt="tcpdump.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The "Install On" is set to the correct VS.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nat.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5015iC207E071B5E0BCE7/image-size/large?v=v2&amp;amp;px=999" role="button" title="nat.png" alt="nat.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/36091"&gt;@funkylicious&lt;/a&gt;: I've just added an explicit rule as you suggested, but that traffic, I think, should be ensured by Implied Rules... anyway, nothing changed; please see the telnet/tcpdump screenshot above.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5016i5DABF2E684C5D046/image-size/large?v=v2&amp;amp;px=999" role="button" title="rule.png" alt="rule.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 07:46:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79297#M9231</guid>
      <dc:creator>redcrow</dc:creator>
      <dc:date>2020-03-23T07:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79302#M9232</link>
      <description>Just a other question, why do you need the NAT from the VS itself? Normally all updates etc are done from VS0, so if you need anything to be able to go to the internet it would be VS0 not the VS itself.</description>
      <pubDate>Mon, 23 Mar 2020 07:51:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79302#M9232</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-23T07:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79304#M9233</link>
      <description>&lt;P&gt;Since I'd like to enable advanced functionalities, for instance:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/VSX/Blocking-malicious-IP-addresses-sk103154-in-VSX/m-p/78768#M533" target="_blank"&gt;https://community.checkpoint.com/t5/VSX/Blocking-malicious-IP-addresses-sk103154-in-VSX/m-p/78768#M533&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk132193&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 07:56:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79304#M9233</guid>
      <dc:creator>redcrow</dc:creator>
      <dc:date>2020-03-23T07:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Hide NAT of the FW external IP in VSX configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79306#M9234</link>
      <description>Then I would suggest opening a case with TAC</description>
      <pubDate>Mon, 23 Mar 2020 07:57:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Hide-NAT-of-the-FW-external-IP-in-VSX-configuration/m-p/79306#M9234</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-23T07:57:53Z</dc:date>
    </item>
  </channel>
</rss>

