<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Nat through site to site vpn in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/55623#M11122</link>
    <description>&lt;P&gt;One other quick question. When setting up the encryption domain and using NAT, does the real ip and NAT ip have to to be in the source on the enc domain if traffic is initiating from our side ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jun 2019 14:30:23 GMT</pubDate>
    <dc:creator>JonWilliams</dc:creator>
    <dc:date>2019-06-12T14:30:23Z</dc:date>
    <item>
      <title>Nat through site to site vpn</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/55599#M11116</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to setup a nat through a site to site vpn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have a weird setup where our internal source is a public ip /32 talking to a dest public ip /32. When i do a no nat rule it works ok. Issue being that our internal ip is a public ip address in italy so they cannot route to it.&lt;/P&gt;&lt;P&gt;i then nat our internal to a spare public ip off our cp range and the tunnel breaks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no nat rule is&lt;/P&gt;&lt;P&gt;source ip&amp;nbsp; -&amp;nbsp; dest ip&amp;nbsp; - source nat to public spare ip&lt;/P&gt;&lt;P&gt;dest ip - source ip (Public)&amp;nbsp; - denat dest to real ip&lt;/P&gt;&lt;P&gt;My encruption domain is source (real and public) des(dest public)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help, greatly received,, thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 10:26:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/55599#M11116</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2019-06-12T10:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Nat through site to site vpn</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/55623#M11122</link>
      <description>&lt;P&gt;One other quick question. When setting up the encryption domain and using NAT, does the real ip and NAT ip have to to be in the source on the enc domain if traffic is initiating from our side ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 14:30:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/55623#M11122</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2019-06-12T14:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: Nat through site to site vpn</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/55891#M11190</link>
      <description>You've just described why you shouldn't use public IPs in your internal network unless you own them. &lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;BR /&gt;To see what the actual issue is, you probably need to do some debugging.&lt;BR /&gt;Start here: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34467&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The local encryption domain should contain anything that might initiate a connection, which I believe includes NAT addresses.&lt;BR /&gt;The remote definition for your encryption domain should only include IPs it will see.</description>
      <pubDate>Sun, 16 Jun 2019 00:38:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/55891#M11190</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-16T00:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Nat through site to site vpn</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/55908#M11200</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on both ends the devices only need the (NAT) Adresses, that have to be talked about in IPSEC VPN. The real IPs might be needed on the gateways for Access Lists.&lt;/P&gt;&lt;P&gt;So, when you change the NAT IP, the traffic is not matching the encryption domain anymore and is either routed somewhere else or lost/discarded.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as Phoneboy said. I´d avoid using public IPs, as long they are not reserved for this and i or the customer owns them. But normally that should work..&lt;/P&gt;&lt;P&gt;You will need some further troubleshooting/debugging, i guess. use this to get started: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=skI4326" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=skI4326&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and than have a look at the logs and .elg files&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jun 2019 16:28:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/55908#M11200</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2019-06-16T16:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Nat through site to site vpn</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/55928#M11204</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case we have to target a public ip on their side. My address is local (172) and then we nat to a spare range on our public ip range. My point is that on their asa the cryptomap acl takes care of the acl but on Checkpoint where do i put the access rule to allow my private ip to talk to there public ip. If it is not in our access list entry&amp;nbsp; on our enc domain, wont it take that rule over the enc acl and not use that ? My Checkpoint exp is limited, sorry. Does it not matter where i put the private ip to their dest acl entry ?&amp;nbsp; When i add a the real ip on the acl to allow my source to talk to their public ip, it uses that rule and does not use the enc domain rule where the nat source is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2019 07:08:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/55928#M11204</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2019-06-17T07:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: Nat through site to site vpn</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/55998#M11222</link>
      <description>The encryption domain definition for the remote site would have to include any IP you are initiating a connection to.&lt;BR /&gt;In this case, it would need to include the public address(es).&lt;BR /&gt;This is defined on the gateway object for the remote site.</description>
      <pubDate>Mon, 17 Jun 2019 18:06:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/55998#M11222</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-17T18:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Nat through site to site vpn</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/56029#M11240</link>
      <description>&lt;P&gt;Thanks, im guessing the enc domain would also have to include our internal source ip as well ?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 07:16:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/56029#M11240</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2019-06-18T07:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: Nat through site to site vpn</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/56198#M11315</link>
      <description>&lt;P&gt;hi PhoneBoy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you confirm the answer to my last question please.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2019 15:32:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/56198#M11315</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2019-06-19T15:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Nat through site to site vpn</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/56201#M11317</link>
      <description>Yes it would.</description>
      <pubDate>Wed, 19 Jun 2019 16:27:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Nat-through-site-to-site-vpn/m-p/56201#M11317</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-19T16:27:32Z</dc:date>
    </item>
  </channel>
</rss>

