<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT through VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/NAT-through-VPN/m-p/55935#M11206</link>
    <description>&lt;P&gt;my enc domain rule is&lt;/P&gt;&lt;P&gt;source 87.x.x.x /255 talking to a public ip (third party) host /32&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nat rule is bi directional nat&amp;nbsp;&lt;/P&gt;&lt;P&gt;outbound - 172.x.x..x/32 - public ip&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat source original - dest nat to 87.x.x.x.x/32&lt;/P&gt;&lt;P&gt;inbound - public ip (third party)&amp;nbsp; dest 87.x.x.x/32&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dest - denat to 172.x.x.x./32&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Natting works ok&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my issue is that as our enc domain acl does not contain the real ip i have to add a acl to he gateway which is&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source - 172.x.x.x/32 to public ip (third party) host /32&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So when i initiate the traffic from my sourc ip, it uses the acl rule and not the rule on the enc domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have to target a public ip on their side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jun 2019 08:46:42 GMT</pubDate>
    <dc:creator>JonWilliams</dc:creator>
    <dc:date>2019-06-17T08:46:42Z</dc:date>
    <item>
      <title>NAT through VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-through-VPN/m-p/55697#M11144</link>
      <description>&lt;P&gt;Hi, i am trying to setup a vpn to a asa and we are natting on our side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On their enc domain (crypto acl) they only have our nat address as their destination.&lt;/P&gt;&lt;P&gt;Am i right in thinking that on our side i have to have the real and nat adress as the source on our side (Enc domain) ? If i only have the nat address, i have to add a normal acl to allow the real address through to talk to the destination and it will always use that rather than the enc domain rule ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry, my Checkpoint exp is limited. Any help gratefully received.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 11:23:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-through-VPN/m-p/55697#M11144</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2019-06-13T11:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: NAT through VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-through-VPN/m-p/55862#M11186</link>
      <description>It would help if you could describe the actual encryption domains with IPs.&lt;BR /&gt;They don't have to be the real IPs but it would help to see how the IPs relate to each other.</description>
      <pubDate>Sat, 15 Jun 2019 04:49:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-through-VPN/m-p/55862#M11186</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-15T04:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: NAT through VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-through-VPN/m-p/55927#M11203</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case we have to target a public ip on their side. My address is local (172) and then we nat to a spare range on our public ip range. My point is that on their asa the cryptomap acl takes care of the acl but on Checkpoint where do i put the access rule to allow my private ip to talk to there public ip. If it is not in our access list entry&amp;nbsp; on our enc domain, wont it take that rule over the enc acl and not use that ? My Checkpoint exp is limited, sorry. Does it not matter where i put the private ip to their dest acl entry ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2019 07:06:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-through-VPN/m-p/55927#M11203</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2019-06-17T07:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: NAT through VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-through-VPN/m-p/55929#M11205</link>
      <description>&lt;P&gt;When i add a the real ip on the acl to allow my source to talk to their public ip, it uses that rule and does not use the enc domain rule where the nat source is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2019 07:09:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-through-VPN/m-p/55929#M11205</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2019-06-17T07:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: NAT through VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-through-VPN/m-p/55935#M11206</link>
      <description>&lt;P&gt;my enc domain rule is&lt;/P&gt;&lt;P&gt;source 87.x.x.x /255 talking to a public ip (third party) host /32&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nat rule is bi directional nat&amp;nbsp;&lt;/P&gt;&lt;P&gt;outbound - 172.x.x..x/32 - public ip&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat source original - dest nat to 87.x.x.x.x/32&lt;/P&gt;&lt;P&gt;inbound - public ip (third party)&amp;nbsp; dest 87.x.x.x/32&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dest - denat to 172.x.x.x./32&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Natting works ok&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my issue is that as our enc domain acl does not contain the real ip i have to add a acl to he gateway which is&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source - 172.x.x.x/32 to public ip (third party) host /32&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So when i initiate the traffic from my sourc ip, it uses the acl rule and not the rule on the enc domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have to target a public ip on their side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2019 08:46:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-through-VPN/m-p/55935#M11206</guid>
      <dc:creator>JonWilliams</dc:creator>
      <dc:date>2019-06-17T08:46:42Z</dc:date>
    </item>
  </channel>
</rss>

