<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic from FW takes External IP in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Traffic-from-FW-takes-External-IP/m-p/60627#M12277</link>
    <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;We need to configure all firewall in the remote location with Centralized NTP.&amp;nbsp; NTP is in HO and we are connecting remote sites only through VPN. Remote Firewalls&amp;nbsp; are not able to connect to NTP and not able to ping.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the tracker we identified the Remote Firewall takes its External Public&amp;nbsp; IP as the source and is dropped in the HO FW,&amp;nbsp; as encryption domain IP is only allowed.&lt;/P&gt;&lt;P&gt;The firewall is configured with HO DNS and nslookup&amp;nbsp; from the Remote FWs is resolving with the HO DNS .&lt;/P&gt;&lt;P&gt;All other communication other than nslookup is taking the Public IP to reach HO DNS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Aug 2019 13:02:14 GMT</pubDate>
    <dc:creator>sajin</dc:creator>
    <dc:date>2019-08-19T13:02:14Z</dc:date>
    <item>
      <title>Traffic from FW takes External IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-from-FW-takes-External-IP/m-p/60627#M12277</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;We need to configure all firewall in the remote location with Centralized NTP.&amp;nbsp; NTP is in HO and we are connecting remote sites only through VPN. Remote Firewalls&amp;nbsp; are not able to connect to NTP and not able to ping.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the tracker we identified the Remote Firewall takes its External Public&amp;nbsp; IP as the source and is dropped in the HO FW,&amp;nbsp; as encryption domain IP is only allowed.&lt;/P&gt;&lt;P&gt;The firewall is configured with HO DNS and nslookup&amp;nbsp; from the Remote FWs is resolving with the HO DNS .&lt;/P&gt;&lt;P&gt;All other communication other than nslookup is taking the Public IP to reach HO DNS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 13:02:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-from-FW-takes-External-IP/m-p/60627#M12277</guid>
      <dc:creator>sajin</dc:creator>
      <dc:date>2019-08-19T13:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from FW takes External IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-from-FW-takes-External-IP/m-p/60636#M12281</link>
      <description>Try to change the VPN community and set the option: Disable NAT inside the VPN community.&lt;BR /&gt;You can also try to setup a NAT rule to make sure that you use the internal interface IP when you access NTP server, or any of the other services that do not work properly.&lt;BR /&gt;It can also be part of the implied rules, which among other things LDAP is one of.</description>
      <pubDate>Mon, 19 Aug 2019 14:10:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-from-FW-takes-External-IP/m-p/60636#M12281</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-08-19T14:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from FW takes External IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-from-FW-takes-External-IP/m-p/60650#M12286</link>
      <description>&lt;P&gt;NO NAT rule is present between Encryption Domains. Is it mandatory to Disable NAT in the community?.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 17:11:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-from-FW-takes-External-IP/m-p/60650#M12286</guid>
      <dc:creator>sajin</dc:creator>
      <dc:date>2019-08-19T17:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: Traffic from FW takes External IP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Traffic-from-FW-takes-External-IP/m-p/60653#M12289</link>
      <description>&lt;P&gt;sajin,&lt;/P&gt;&lt;P&gt;maybe you have configured automatic NAT on the firewall object or on the network object ?&lt;/P&gt;&lt;P&gt;Disabling NAT in the VPN community is not mandatory, but if enabled no NAT is done for the connection going through the VPN tunnel, whatever is configured in the NAT rulebase.&lt;/P&gt;&lt;P&gt;Wolfgang.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 17:41:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Traffic-from-FW-takes-External-IP/m-p/60653#M12289</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-08-19T17:41:19Z</dc:date>
    </item>
  </channel>
</rss>

