<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Loopback configuration problem in R80.10 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20932#M98798</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&amp;nbsp; Kenny,&lt;/P&gt;&lt;P&gt;I have now cleared all connections table with out any change.&lt;/P&gt;&lt;P&gt;Yes i do have the&amp;nbsp; "&lt;EM&gt;&lt;STRONG&gt;NAT --&amp;gt; Manual NAT Rules --&amp;gt;&lt;/STRONG&gt;&lt;/EM&gt; &lt;EM&gt;&lt;STRONG&gt;Translate destination on client side&lt;/STRONG&gt;&lt;/EM&gt; " set to enable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;- The server DemoLEMiCCE is on the same 192.168.0.0/24 subnet.&lt;/P&gt;&lt;P&gt;That is correct&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;- The address on the gateway object is 192.168.0.1 or a new object with this address was created.&lt;/P&gt;&lt;P&gt;That is correct&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; - The manual NAT rule for Source Translation is working as Hide NAT.&lt;/P&gt;&lt;P&gt;That is correct&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can it be a routing table problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//Kristian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Jan 2018 14:08:54 GMT</pubDate>
    <dc:creator>Kristian_Nyquis</dc:creator>
    <dc:date>2018-01-03T14:08:54Z</dc:date>
    <item>
      <title>NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20924#M98790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have problem to configure a hairpin NAT (NAT Loopback) on my system.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a local Lan that is 192.168.0.0/24&lt;/P&gt;&lt;P&gt;On the wan side I have xx.xx.xx.107 that is where all “normal” traffic is using without any problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have xx.xx.xx.122 where I NAT https to an internal server.&lt;/P&gt;&lt;P&gt;I can access the https NAT server from an external IP&lt;/P&gt;&lt;P&gt;When I try to access the https external IP from an internal IP on the Lan side (192.168.0.0/24) it is not possible to access the service. In the log file for the access control policy I get an entry that the client is going out to access the external ip. I do not get a log entry for denied or allowed for the access back to the https service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been reading the &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110019"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110019&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But I do not it to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The config I have in my NAT rules is according to the attached picture. What is it that I am missing?&lt;/P&gt;&lt;P&gt;Is my NAT rules in the incorrect order?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jan 2018 08:39:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20924#M98790</guid>
      <dc:creator>Kristian_Nyquis</dc:creator>
      <dc:date>2018-01-02T08:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20925#M98791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kristian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are accessing https NAT server from locally, why you are doing such lengthy process. It should be within your LAN or should be between DMZ to LAN. Means connectivity is between your private IPs, No need to do NAT.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jan 2018 10:24:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20925#M98791</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-01-02T10:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20926#M98792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gaurav,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately i need to use the WAN IP in this case to get full functionality on the webpage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//Kristian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jan 2018 11:24:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20926#M98792</guid>
      <dc:creator>Kristian_Nyquis</dc:creator>
      <dc:date>2018-01-02T11:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20927#M98793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kristian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110019"&gt;Hairpin NAT SK&lt;/A&gt; you have to create two rules when the traffic is originated from the LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The important thing to returning traffic is the translated source, that shoud be the gateway address. You must create a new host object with the IP address of the gateway (if you have the LAN address as IP of the main GW object, it should work without create a new one) on the translated interface (i assumpt this is the same 192.168.0.0/24 LAN):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="2" height="262" style="text-align: center; width: 702px;"&gt;&lt;TBODY&gt;&lt;TR style="background-color: #576372; color: white; font-weight: bold;"&gt;&lt;TD style="width: 22px;"&gt;No.&lt;/TD&gt;&lt;TD style="width: 111px;"&gt;Original&lt;BR /&gt;Source&lt;/TD&gt;&lt;TD style="width: 67px;"&gt;Original&lt;BR /&gt;Destination&lt;/TD&gt;&lt;TD style="width: 57px;"&gt;Original&lt;BR /&gt;Services&lt;/TD&gt;&lt;TD style="width: 89px;"&gt;Translated&lt;BR /&gt;Source&lt;/TD&gt;&lt;TD style="width: 90px;"&gt;Translated&lt;BR /&gt;Destination&lt;/TD&gt;&lt;TD style="width: 108px;"&gt;Translated&lt;BR /&gt;Services&lt;/TD&gt;&lt;TD style="width: 99px;"&gt;Install On&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="width: 22px;"&gt;1&lt;/TD&gt;&lt;TD style="width: 111px;"&gt;LOCAL LAN&lt;BR /&gt;192.168.0.0/24&lt;/TD&gt;&lt;TD style="width: 67px;"&gt;&lt;P&gt;PUBLIC SERVER&lt;/P&gt;&lt;P&gt;Extern .122&lt;/P&gt;&lt;/TD&gt;&lt;TD style="width: 57px;"&gt;&lt;CODE&gt;https&lt;/CODE&gt;&lt;/TD&gt;&lt;TD style="width: 89px;"&gt;&lt;P&gt;GW LOCAL LAN IP&lt;/P&gt;&lt;P&gt;192.168.0.1&lt;/P&gt;&lt;/TD&gt;&lt;TD style="width: 90px;"&gt;SERVER PRIVATE IP&lt;BR /&gt;DemoLEMiCCE&lt;/TD&gt;&lt;TD style="width: 108px;"&gt;&lt;CODE&gt;= Original&lt;/CODE&gt;&lt;/TD&gt;&lt;TD style="width: 99px;"&gt;Security&lt;BR /&gt;Gateway&lt;BR /&gt;object&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="width: 22px;"&gt;2&lt;/TD&gt;&lt;TD style="width: 111px;"&gt;SERVER PRIVATE IP&lt;BR /&gt;DemoLEMiCCE&lt;/TD&gt;&lt;TD style="width: 67px;"&gt;LOCAL LAN&lt;BR /&gt;192.168.0.0/24&lt;/TD&gt;&lt;TD style="width: 57px;"&gt;&lt;CODE&gt;https&lt;/CODE&gt;&lt;/TD&gt;&lt;TD style="width: 89px;"&gt;&lt;P&gt;PUBLIC SERVER&lt;/P&gt;&lt;P&gt;Extern .122&lt;/P&gt;&lt;/TD&gt;&lt;TD style="width: 90px;"&gt;&lt;CODE&gt;= Original&lt;/CODE&gt;&lt;/TD&gt;&lt;TD style="width: 108px;"&gt;&lt;CODE&gt;= Original&lt;/CODE&gt;&lt;/TD&gt;&lt;TD style="width: 99px;"&gt;Security&lt;BR /&gt;Gateway&lt;BR /&gt;object&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to put the rules at the top of your NAT rulebase, before Automatic Hide NAT and Manual lower rules to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jan 2018 13:54:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20927#M98793</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-01-02T13:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20928#M98794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok Kristian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In that case, you can check the Kenny's Suggestion.&lt;/P&gt;&lt;P&gt;Hope you have different subnet for LAN as well as for servers (DMZ).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jan 2018 15:03:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20928#M98794</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-01-02T15:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20929#M98795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could also try this for the first rule:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;source&amp;nbsp; dest&amp;nbsp; x-source&amp;nbsp; x-dest&lt;/P&gt;&lt;P&gt;192.x&amp;nbsp;&amp;nbsp; x.122&amp;nbsp;&amp;nbsp; original &amp;nbsp; x.122(private)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This basically says not to translate LAN traffic source, but to translate DMZ server destination.&amp;nbsp; Return traffic would come back and be translated via Kenny's second rule above just fine.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 06:36:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20929#M98795</guid>
      <dc:creator>Michael_Lawrenc</dc:creator>
      <dc:date>2018-01-03T06:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20930#M98796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kenny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have implemented your suggestion in my system and i do not get any change in behaviour.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still get the connection from the internal network when using the WAN address.&lt;/P&gt;&lt;P&gt;I have performed a tcpdump with help of "&lt;EM&gt;&lt;STRONG&gt;fw monitor -e "accept;" -o /var/log/fw_mon.cap&lt;/STRONG&gt;&lt;/EM&gt;" in the expert mode and in the cap file i get the connection attempt from the internal network to the internal fw address.&lt;/P&gt;&lt;P&gt;I do not get any traffic back to the internal network from the fw in the cap file. When i perform the same cmd using external machine accessing the service i get the complete tcp flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other setting that i need to perform to get this to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//Kristian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 12:39:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20930#M98796</guid>
      <dc:creator>Kristian_Nyquis</dc:creator>
      <dc:date>2018-01-03T12:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20931#M98797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kristian&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you reviewed the connections table in case there is an old session without NAT for this? Sometime ago I had that problem and had to clear the specific connection (clear all connections table also works).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The connection on fw monitor should be seen as something like this if the LAN users are pointing to external address to access the server (dont forget to disable SecureXL):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;[internal_interface.&lt;STRONG&gt;i&lt;/STRONG&gt;] 192.168.0.0/24:xxxxx --&amp;gt; Extern .122:443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;[internal_interface.&lt;STRONG&gt;I&lt;/STRONG&gt;] 192.168.0.0/24:xxxxx --&amp;gt; DemoLEMiCCE:443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;[internal_interface.&lt;STRONG&gt;o&lt;/STRONG&gt;] 192.168.0.0/24:xxxxx --&amp;gt; DemoLEMiCCE::443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;[internal_interface.&lt;STRONG&gt;O&lt;/STRONG&gt;] 192.168.0.1:xxxxx --&amp;gt; DemoLEMiCCE:443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following conditions are assumed on this scenario:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;- The server DemoLEMiCCE is on the same 192.168.0.0/24 subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;- The address on the gateway object is 192.168.0.1 or a new object with this address was created.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; - The first manual NAT rule for Source Translation of the LAN is working as Hide NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;- The option &lt;EM&gt;&lt;STRONG&gt;NAT --&amp;gt; Manual NAT Rules --&amp;gt;&lt;/STRONG&gt;&lt;/EM&gt; &lt;EM&gt;&lt;STRONG&gt;Translate destination on client side&lt;/STRONG&gt;&lt;/EM&gt; is enabled in Global Properties.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 13:05:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20931#M98797</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-01-03T13:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20932#M98798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&amp;nbsp; Kenny,&lt;/P&gt;&lt;P&gt;I have now cleared all connections table with out any change.&lt;/P&gt;&lt;P&gt;Yes i do have the&amp;nbsp; "&lt;EM&gt;&lt;STRONG&gt;NAT --&amp;gt; Manual NAT Rules --&amp;gt;&lt;/STRONG&gt;&lt;/EM&gt; &lt;EM&gt;&lt;STRONG&gt;Translate destination on client side&lt;/STRONG&gt;&lt;/EM&gt; " set to enable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;- The server DemoLEMiCCE is on the same 192.168.0.0/24 subnet.&lt;/P&gt;&lt;P&gt;That is correct&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;- The address on the gateway object is 192.168.0.1 or a new object with this address was created.&lt;/P&gt;&lt;P&gt;That is correct&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; - The manual NAT rule for Source Translation is working as Hide NAT.&lt;/P&gt;&lt;P&gt;That is correct&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can it be a routing table problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//Kristian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 14:08:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20932#M98798</guid>
      <dc:creator>Kristian_Nyquis</dc:creator>
      <dc:date>2018-01-03T14:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20933#M98799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont think this is a routing problem because you have directly connected the LAN and external interfaces, also Translate destination on client side is enabled (avoiding you to create a static route).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you attach an screenshot of your manual NAT rules for this?&lt;/P&gt;&lt;P&gt;Also if you can make an fw monitor capture filtering the involved hosts (external and internal addreses) like this one:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;fw monitor -e "(net(192.168.0.0,24) and host(Extern.122_IP_ADDRESS)) or (net(192.168.0.0,24) and host(DemoLEMiCCE_IP_ADDRESS)), accept;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 14:16:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20933#M98799</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-01-03T14:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20934#M98800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I get the following:&lt;/P&gt;&lt;P&gt;[vs_0][fw_0] eth5:i[52]: 192.168.0.6 -&amp;gt; xxx.xxx.xxx.122 (TCP) len=52 id=14798&lt;BR /&gt;TCP: 56715 -&amp;gt; 443 .S.... seq=8b9cf060 ack=00000000&lt;BR /&gt;[vs_0][fw_0] eth5:I[52]: 192.168.0.6 -&amp;gt; 192.168.0.31 (TCP) len=52 id=14798&lt;BR /&gt;TCP: 56715 -&amp;gt; 443 .S.... seq=8b9cf060 ack=00000000&lt;BR /&gt;[vs_0][fw_0] eth5:o[52]: 192.168.0.6 -&amp;gt; 192.168.0.31 (TCP) len=52 id=14798&lt;BR /&gt;TCP: 56715 -&amp;gt; 443 .S.... seq=8b9cf060 ack=00000000&lt;BR /&gt;[vs_0][fw_0] eth5:O[52]: 192.168.0.6 -&amp;gt; 192.168.0.31 (TCP) len=52 id=14798&lt;BR /&gt;TCP: 56715 -&amp;gt; 443 .S.... seq=8b9cf060 ack=00000000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when running:&lt;/P&gt;&lt;P&gt;fw monitor -e "host(192.168.0.6) or host(192.168.0.31) or host(xx.xx.xx.122) or host(192.168.0.252) and port(443), accept;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did re-run my wireshark on 192.168.0.6 and 192.168.0.31 (DemoLEMiCCE)&lt;/P&gt;&lt;P&gt;Now I get traffic between these two hosts on port 443 but the web browser is not is not displaying the page.&lt;/P&gt;&lt;P&gt;In the attachment is a tcpdump from the client machine .6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bellow is my NAT rules&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="61663" alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61663_NATrules.png" style="width: 620px; height: 430px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 14:38:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20934#M98800</guid>
      <dc:creator>Kristian_Nyquis</dc:creator>
      <dc:date>2018-01-03T14:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20935#M98801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems you're not translating the source of 192.168.0.0/24 LAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to capture, packet is leaving the interface with original address 192.168.0.6:&lt;/P&gt;&lt;P&gt;[vs_0][fw_0] eth5:i[52]: 192.168.0.6 -&amp;gt; xxx.xxx.xxx.122 (TCP) len=52 id=14798&lt;BR /&gt;TCP: 56715 -&amp;gt; 443 .S.... seq=8b9cf060 ack=00000000&lt;BR /&gt;[vs_0][fw_0] eth5:I[52]: 192.168.0.6 -&amp;gt; 192.168.0.31 (TCP) len=52 id=14798&lt;BR /&gt;TCP: 56715 -&amp;gt; 443 .S.... seq=8b9cf060 ack=00000000&lt;BR /&gt;[vs_0][fw_0] eth5:o[52]: 192.168.0.6 -&amp;gt; 192.168.0.31 (TCP) len=52 id=14798&lt;BR /&gt;TCP: 56715 -&amp;gt; 443 .S.... seq=8b9cf060 ack=00000000&lt;BR /&gt;&lt;STRONG&gt;[vs_0][fw_0] eth5:O[52]: 192.168.0.6 -&amp;gt; 192.168.0.31 (TCP) len=52 id=14798&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;TCP: 56715 -&amp;gt; 443 .S.... seq=8b9cf060 ack=00000000&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On your NAT rule number 1 Translated Source is missing, you need to put here the object with the gateway address (for your capture I think is 192.168.0.252) and configure as hide nat (Right click --&amp;gt; NAT Method --&amp;gt; Hide)&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="61670" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61670_pastedImage_11.png" style="width: 620px; height: 47px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Otherwise, your server "thinks" this is local traffic due to the 192.168.0.6 hosts is in its same subnet and does not need to send the reply traffic to default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 14:49:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20935#M98801</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-01-03T14:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20936#M98802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did that and now i get 192.168.1.2 as the return address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[vs_0][fw_1] eth5:i[52]: 192.168.0.6 -&amp;gt; xx.xx.xx.122 (TCP) len=52 id=31345&lt;BR /&gt;TCP: 56818 -&amp;gt; 443 .S.... seq=48a67142 ack=00000000&lt;BR /&gt;[vs_0][fw_1] eth5:I[52]: 192.168.0.6 -&amp;gt; 192.168.0.31 (TCP) len=52 id=31345&lt;BR /&gt;TCP: 56818 -&amp;gt; 443 .S.... seq=48a67142 ack=00000000&lt;BR /&gt;[vs_0][fw_1] eth5:o[52]: 192.168.0.6 -&amp;gt; 192.168.0.31 (TCP) len=52 id=31345&lt;BR /&gt;TCP: 56818 -&amp;gt; 443 .S.... seq=48a67142 ack=00000000&lt;BR /&gt;[vs_0][fw_1] eth5:O[52]: 192.168.1.2 -&amp;gt; 192.168.0.31 (TCP) len=52 id=31345&lt;BR /&gt;TCP: 56818 -&amp;gt; 443 .S.... seq=48a67142 ack=00000000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The translated source i was forced to create as a network ( the same type on original and translated)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the question is where does the 192.168.1.2 come from&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="61673" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61673_pastedImage_1.png" style="width: 620px; height: 467px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 15:08:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20936#M98802</guid>
      <dc:creator>Kristian_Nyquis</dc:creator>
      <dc:date>2018-01-03T15:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20937#M98803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have created a network object with /32 mask, is the most probably cause for wrong translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The easiest way to do this is create a new host object and put the gateway IP on the 192.168.0.0/24 subnet. After this, you configure it as Translated Source Right click --&amp;gt; NAT Method --&amp;gt; Hide so this way all the subnet is nated as hide with gateway address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have configured the gateway with the LAN address like this:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61672_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to use gateway object as translated source (hide also) without create the host object mentioned above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 15:20:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20937#M98803</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-01-03T15:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20938#M98804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not allowed to use the host object in this case:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61674_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because on the Original source a network range is used and then that is also need on the translated source.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have now created a network range according to the following:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61675_pastedImage_2.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then it is possible to access the server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 15:33:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20938#M98804</guid>
      <dc:creator>Kristian_Nyquis</dc:creator>
      <dc:date>2018-01-03T15:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20939#M98805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have not changed the NAT method to Hide, that's why you got an error about range size. Static NAT its trying to translate a /24 subnet to a /32, and this cant be done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you use a host object or gateway object and configure hide nat on nat rulebase, it will work.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61676_pastedImage_3.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 15:43:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20939#M98805</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-01-03T15:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20940#M98806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That worked, thank you for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did miss that button for the nat method, i did only change it according to bellow:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="61679" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61679_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 15:52:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20940#M98806</guid>
      <dc:creator>Kristian_Nyquis</dc:creator>
      <dc:date>2018-01-03T15:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20941#M98807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great to hear it works!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When you configure NAT on the object, it goes straight to Automatic NAT rules for that object only (below your manual NAT rules).&lt;/P&gt;&lt;P&gt;For manual NAT rules, you need to specify the method for the translated object through right click.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, thanks for the badge! &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/grin.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 15:59:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20941#M98807</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-01-03T15:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20942#M98808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is one of the many reasons why you should NEVER setup your Internet accessible servers in the normal LAN.&lt;/P&gt;&lt;P&gt;Always use a DMZ on the FW, that way you control the traffic from that server to the rest of the network as well. This scenario is just one of the issues we see quite a lot of times with our customers that do not use a DMZ Network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2018 19:22:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20942#M98808</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-01-03T19:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Loopback configuration problem in R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20943#M98809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah.&amp;nbsp;It is&amp;nbsp;best security practice to separate Server-DMZ zone so that it can be easily managed and secured.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jan 2018 04:16:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Loopback-configuration-problem-in-R80-10/m-p/20943#M98809</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-01-04T04:16:27Z</dc:date>
    </item>
  </channel>
</rss>

