<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Manual NAT inside a VPN IPsec Tunnel in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Manual-NAT-inside-a-VPN-IPsec-Tunnel/m-p/10440#M1488</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I setup up a IPsec tunnel between checkpoint and a 3rd party VPN. Everything works fine without any problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question is that when I connect one router (R1) to the gateway(R77.30) and put one PC(WS2012R2-4) behind the router the tunnel not worked as expected.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="79808" alt="" class="j-img-centered image-4 jive-image" height="328" src="/legacyfs/online/checkpoint/79808_Screenshot from 2019-03-05 21-42-54.png" style="display: block; margin-left: auto; margin-right: auto;" width="337" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Behind the router I have the network 10.1.1.0/24 and I do some NAT manipulation on the gateway, like that:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="79804" alt="" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/79804_Screenshot from 2019-03-05 21-19-23.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I want to manipulate the traffic coming from the PC 10.1.1.10 to appear in the tunnel on the other side with the Source 172.16.3.20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I setup my firewall rule to work with the VPN Community, like that:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="79805" alt="" class="image-2 jive-image j-img-original" src="/legacyfs/online/checkpoint/79805_Screenshot from 2019-03-05 21-27-30.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The VPN Domains in both sides are the Networks: 172.16.3.0/24(Checkpoint) and 172.16.1.0/24(Fortinet).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that host 10.1.1.10 cannot fire up the tunnel and all other hosts on the network 172.16.3.0/24 can setup the tunnel. I don't have the NAT disabled on the Community and the gateway and router have routes setting up for routing purposes, I don't think this is a routing issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I captured traffic with the wireshark from the outside interface eth0 (See the topology above), and I forced traffic through the tunnel with the PC 10.1.1.10, but nothing happened, please see below the packets:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="79809" alt="" class="image-5 jive-image j-img-original" src="/legacyfs/online/checkpoint/79809_Screenshot from 2019-03-05 21-56-05.png" /&gt;&lt;/P&gt;&lt;P&gt;Source NAT works fine, but I cannot setup the tunnel, why this happen?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I doing wrong? What is left to do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advanced&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Mar 2019 21:59:42 GMT</pubDate>
    <dc:creator>Luis_Filipe</dc:creator>
    <dc:date>2019-03-05T21:59:42Z</dc:date>
    <item>
      <title>Manual NAT inside a VPN IPsec Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manual-NAT-inside-a-VPN-IPsec-Tunnel/m-p/10440#M1488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I setup up a IPsec tunnel between checkpoint and a 3rd party VPN. Everything works fine without any problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question is that when I connect one router (R1) to the gateway(R77.30) and put one PC(WS2012R2-4) behind the router the tunnel not worked as expected.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="79808" alt="" class="j-img-centered image-4 jive-image" height="328" src="/legacyfs/online/checkpoint/79808_Screenshot from 2019-03-05 21-42-54.png" style="display: block; margin-left: auto; margin-right: auto;" width="337" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Behind the router I have the network 10.1.1.0/24 and I do some NAT manipulation on the gateway, like that:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="79804" alt="" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/79804_Screenshot from 2019-03-05 21-19-23.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I want to manipulate the traffic coming from the PC 10.1.1.10 to appear in the tunnel on the other side with the Source 172.16.3.20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I setup my firewall rule to work with the VPN Community, like that:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="79805" alt="" class="image-2 jive-image j-img-original" src="/legacyfs/online/checkpoint/79805_Screenshot from 2019-03-05 21-27-30.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The VPN Domains in both sides are the Networks: 172.16.3.0/24(Checkpoint) and 172.16.1.0/24(Fortinet).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that host 10.1.1.10 cannot fire up the tunnel and all other hosts on the network 172.16.3.0/24 can setup the tunnel. I don't have the NAT disabled on the Community and the gateway and router have routes setting up for routing purposes, I don't think this is a routing issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I captured traffic with the wireshark from the outside interface eth0 (See the topology above), and I forced traffic through the tunnel with the PC 10.1.1.10, but nothing happened, please see below the packets:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="79809" alt="" class="image-5 jive-image j-img-original" src="/legacyfs/online/checkpoint/79809_Screenshot from 2019-03-05 21-56-05.png" /&gt;&lt;/P&gt;&lt;P&gt;Source NAT works fine, but I cannot setup the tunnel, why this happen?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I doing wrong? What is left to do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advanced&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2019 21:59:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manual-NAT-inside-a-VPN-IPsec-Tunnel/m-p/10440#M1488</guid>
      <dc:creator>Luis_Filipe</dc:creator>
      <dc:date>2019-03-05T21:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT inside a VPN IPsec Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manual-NAT-inside-a-VPN-IPsec-Tunnel/m-p/10441#M1489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try using Dead Peer Detection. It should keep the tunnel up.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec"&gt;VPN Site-to-Site with 3rd party&lt;/A&gt;&amp;nbsp;Scenario 5.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2019 22:45:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manual-NAT-inside-a-VPN-IPsec-Tunnel/m-p/10441#M1489</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-03-05T22:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT inside a VPN IPsec Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manual-NAT-inside-a-VPN-IPsec-Tunnel/m-p/10442#M1490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Luis,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as I understand your traffic capture is from eth0 and this is the external interface of your firewall.&lt;/P&gt;&lt;P&gt;If you did the capture with tcpdump&amp;nbsp;you should never see the NATed packet on eth0, the packet should be decrypt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should add net 10.1.1.0/24 or the one host 10.1.1.10 to your local encryption domain on the CheckPoint gateway.&lt;/P&gt;&lt;P&gt;And in the rulebase you too need to allow this net to pass th VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2019 08:03:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manual-NAT-inside-a-VPN-IPsec-Tunnel/m-p/10442#M1490</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-03-06T08:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT inside a VPN IPsec Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Manual-NAT-inside-a-VPN-IPsec-Tunnel/m-p/10443#M1491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see that you have ARP traffic from 10. network on your external Check Point interface's packet capture.&lt;/P&gt;&lt;P&gt;If you are building this environment in GNS, beware:) some weirdness is expected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2019 22:57:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Manual-NAT-inside-a-VPN-IPsec-Tunnel/m-p/10443#M1491</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-03-06T22:57:33Z</dc:date>
    </item>
  </channel>
</rss>

