<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static NAT. Simple question. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-NAT-Simple-question/m-p/13432#M99489</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/60997_Snap.JPG" style="width: 620px; height: 57px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Nov 2017 15:06:24 GMT</pubDate>
    <dc:creator>Gaurav_Pandya</dc:creator>
    <dc:date>2017-11-20T15:06:24Z</dc:date>
    <item>
      <title>Static NAT. Simple question.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-NAT-Simple-question/m-p/13428#M99485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a firewall 5400.&amp;nbsp;On the firewall three interfaces:&lt;/P&gt;&lt;P&gt;1. LAN - 10.1.1.1&lt;/P&gt;&lt;P&gt;2. DMZ - 172.16.0.1&lt;/P&gt;&lt;P&gt;3. EXTERNAL- 85.1.1.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is necessary to publish the web server (on the local network) outside so that:&lt;/P&gt;&lt;P&gt;1. WEB server (LAN)&amp;lt;-&amp;gt;DMZ -&amp;nbsp;without NAT&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;External &amp;lt;-&amp;gt;&amp;nbsp;WEB server (LAN) - via a specific ip address (85.1.1.105)&lt;/P&gt;&lt;P&gt;3. WEB server (LAN)&amp;nbsp;&lt;SPAN&gt;&amp;lt;-&amp;gt;External - &lt;SPAN&gt;via a specific&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;ip&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;address (85.1.1.105)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;How to write a static NAT rule I understand, but how to make sure that traffic is not between&amp;nbsp;Web server and DMZ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 10:52:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-NAT-Simple-question/m-p/13428#M99485</guid>
      <dc:creator>Andrew25</dc:creator>
      <dc:date>2017-11-20T10:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT. Simple question.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-NAT-Simple-question/m-p/13429#M99486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There should be subnets defined in LAN as well as in DMZ. so you can make groups of LAN subnet and DMZ subnet. After that you can put Manual NAT rule from LAN to DMZ and vice versa with No NAT. For remaining traffic you can use static NAT.&lt;/P&gt;&lt;P&gt;Hope I answered your question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 13:37:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-NAT-Simple-question/m-p/13429#M99486</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2017-11-20T13:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT. Simple question.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-NAT-Simple-question/m-p/13430#M99487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How to make a rule without NAT, can show or example lead? Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 13:40:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-NAT-Simple-question/m-p/13430#M99487</guid>
      <dc:creator>Andrew25</dc:creator>
      <dc:date>2017-11-20T13:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT. Simple question.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-NAT-Simple-question/m-p/13431#M99488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can keep packet as "original" in translated packet field.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 15:01:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-NAT-Simple-question/m-p/13431#M99488</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2017-11-20T15:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: Static NAT. Simple question.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-NAT-Simple-question/m-p/13432#M99489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/60997_Snap.JPG" style="width: 620px; height: 57px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 15:06:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-NAT-Simple-question/m-p/13432#M99489</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2017-11-20T15:06:24Z</dc:date>
    </item>
  </channel>
</rss>

