<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN connection with Destination NAT not working in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21813#M95718</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&amp;nbsp; I checked with support and Domain based VPN does not work when the encryption domains overlap.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Jun 2018 11:33:52 GMT</pubDate>
    <dc:creator>Michael_Horne</dc:creator>
    <dc:date>2018-06-06T11:33:52Z</dc:date>
    <item>
      <title>VPN connection with Destination NAT not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21808#M95713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having trouble getting a destination NAT working for a VPN connection working.&amp;nbsp; I am sure it is a simple issue, but I have been banging my head against the wall with it for a couple of days.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a domain based VPN for a site to site VPN. The VPN doman is configured and working as I can bring up the VPN for some other connections that are not using destination NAT. The Interoperable Device is configure with a VPN Domain that includes the "real" and "NAT IP":&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remote &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Local&lt;BR /&gt;192.168.2.10/32 10.0.0.0/8&lt;BR /&gt;10.191.34.10/32 10.0.0.0/8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Access Policy is configure for testing to match from a host HTTP traffic with the VPN configured:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/65388_Policy.PNG" /&gt;&lt;/P&gt;&lt;P&gt;The NAT Policy is configured for a destination NAT from NAT_Server (192.168.2.10) to the H_Server (10.191.34.10)&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/65389_NAT.PNG" /&gt;&lt;/P&gt;&lt;P&gt;My understanding is that this should map the NAT_Server (192.168.2.10) to the H_Server (10.191.34.10).&amp;nbsp; This does appear to work as I see with "fw monitor" the traffic arriving on the firewall on the expected eth1 and trying to leave on the expected eth3:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-3 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/65390_Monitor.PNG" /&gt;&lt;/P&gt;&lt;P&gt;The problem is that the packet stops on the outbound chain "o".&amp;nbsp; In the log files I see the message about encryption failure: Different community ID, possible NAT problem (VPN Error code 01)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-4 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/65392_Log.PNG" /&gt;&lt;/P&gt;&lt;P&gt;If someone is able to guide me in the right direction to solve this, it would be much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 May 2018 10:20:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21808#M95713</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2018-05-07T10:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN connection with Destination NAT not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21809#M95714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like the issue from &lt;EM&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk25867&amp;amp;partition=Advanced&amp;amp;product=IPSec"&gt;sk25867 "Different community ID, possible NAT problem (VPN Error code 02)" error on packet drop&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is also &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec"&gt;&lt;EM&gt;sk108600 VPN Site-to-Site with 3rd party&lt;/EM&gt;&lt;/A&gt;&amp;nbsp; that may help...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 May 2018 12:22:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21809#M95714</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-05-07T12:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN connection with Destination NAT not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21810#M95715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been through many SKs, recently, but I will check them out.&amp;nbsp; I believe I have not looked at sk108600 yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 May 2018 12:30:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21810#M95715</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2018-05-07T12:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN connection with Destination NAT not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21811#M95716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sk108600 is very helpfull for VPN with 3rd Party GWs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 May 2018 12:47:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21811#M95716</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-05-07T12:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN connection with Destination NAT not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21812#M95717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Were you able to resolve the issue yet ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2018 10:54:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21812#M95717</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-06-06T10:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: VPN connection with Destination NAT not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21813#M95718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&amp;nbsp; I checked with support and Domain based VPN does not work when the encryption domains overlap.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2018 11:33:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21813#M95718</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2018-06-06T11:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN connection with Destination NAT not working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21814#M95719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is certainly true &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2018 12:10:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-connection-with-Destination-NAT-not-working/m-p/21814#M95719</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-06-06T12:10:33Z</dc:date>
    </item>
  </channel>
</rss>

