<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Site to Site statically Nated IP address in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site-to-Site-statically-Nated-IP-address/m-p/86477#M17338</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to set a S2S tunnel between two Checkpoints managed by the same SMS (r80.10), but one of them is using a private IP as WAN to connect with the ISP. Then the ISP is routing the public IP to our private IP in the Checkpoint. I am using the Link Selection type of "Statically NATed IP" and I have set there the public IP I would like to use to form the packet. The problem I am seeing is that the tunnel does not get up and I cannot see traffic with tcpdump related to ipesec tunnel. Any idea about what could be happen? I could make a small diagram if you need it. Thank you very much.&lt;/P&gt;</description>
    <pubDate>Wed, 27 May 2020 13:02:53 GMT</pubDate>
    <dc:creator>Gusa2727</dc:creator>
    <dc:date>2020-05-27T13:02:53Z</dc:date>
    <item>
      <title>VPN Site to Site statically Nated IP address</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site-to-Site-statically-Nated-IP-address/m-p/86477#M17338</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to set a S2S tunnel between two Checkpoints managed by the same SMS (r80.10), but one of them is using a private IP as WAN to connect with the ISP. Then the ISP is routing the public IP to our private IP in the Checkpoint. I am using the Link Selection type of "Statically NATed IP" and I have set there the public IP I would like to use to form the packet. The problem I am seeing is that the tunnel does not get up and I cannot see traffic with tcpdump related to ipesec tunnel. Any idea about what could be happen? I could make a small diagram if you need it. Thank you very much.&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 13:02:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site-to-Site-statically-Nated-IP-address/m-p/86477#M17338</guid>
      <dc:creator>Gusa2727</dc:creator>
      <dc:date>2020-05-27T13:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to Site statically Nated IP address</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site-to-Site-statically-Nated-IP-address/m-p/86824#M17432</link>
      <description>That could mean the traffic isn't getting to the gateway at all.&lt;BR /&gt;Which makes this an upstream issue.&lt;BR /&gt;Can you confirm IPSEC traffic is leaving the remote gateway?</description>
      <pubDate>Sun, 31 May 2020 04:32:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site-to-Site-statically-Nated-IP-address/m-p/86824#M17432</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-31T04:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to Site statically Nated IP address</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site-to-Site-statically-Nated-IP-address/m-p/131449#M23840</link>
      <description>&lt;P&gt;I am having the same issue. The VPN works when I have the Main IP activated. But when I then change it to&amp;nbsp;Statically NATed IP the VPN drops and doesn't work.&lt;/P&gt;&lt;P&gt;Nothing shows up in the logs besides in the VPN debug then "Peer Name: Unknown"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Oct 2021 05:45:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site-to-Site-statically-Nated-IP-address/m-p/131449#M23840</guid>
      <dc:creator>carp3di3m</dc:creator>
      <dc:date>2021-10-11T05:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site to Site statically Nated IP address</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site-to-Site-statically-Nated-IP-address/m-p/131472#M23843</link>
      <description>&lt;P&gt;From&amp;nbsp;&lt;SPAN&gt;sk32664:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Before R80.10, Check Point "Maintrain" Security Gateways did not support initiating IKE propositions over NAT-T.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;A Security Gateway will accept and support proposals for industry UDP encapsulation behind port 4500, but&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;will never initiate&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;a proposal, unlike 600, 1100, 1200R and VPN-1 Edge Appliances&amp;nbsp;that do support initiating IKE propositions over NAT-T.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Oct 2021 09:01:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site-to-Site-statically-Nated-IP-address/m-p/131472#M23843</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-10-11T09:01:20Z</dc:date>
    </item>
  </channel>
</rss>

