<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Natting IP address for not DC network in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Natting-IP-address-for-not-DC-network/m-p/112411#M21158</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="check_56_58.png" style="width: 990px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10744iE80388031A618203/image-size/large?v=v2&amp;amp;px=999" role="button" title="check_56_58.png" alt="check_56_58.png" /&gt;&lt;/span&gt;hello&lt;/P&gt;&lt;P&gt;Need natting at fw-1 some hosts which is in aubnet connected to fw-2&lt;/P&gt;&lt;P&gt;we have ClusterXL 5800 gw and some direct connection networks for him and NAT realized here&lt;/P&gt;&lt;P&gt;so&lt;BR /&gt;we have ClusterXL 5600 gw and want to realized NAT here for all networks behind clusterXL 5800 (do it for more secure ;0)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cXL 5800 conected with cXL 5600 by 172.19.19.0/29 network&lt;/P&gt;&lt;P&gt;and cXL 5600 have route to networks behind clusterXL 5800&lt;/P&gt;&lt;P&gt;when, for example, at 5600 ping 10.150.50.10 - success, when ping hpe.com - success&lt;BR /&gt;thus 5600 have conncect for internal and external networks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;# 10.150.50.10 -&amp;gt; 193.100.200.74 (web server)&lt;/P&gt;&lt;P&gt;so&lt;BR /&gt;do auto NAT 10.150.50.10 -&amp;gt; 193.100.200.74 for cXL 5800 (only) - and check it&lt;/P&gt;&lt;P&gt;All ok, its works&lt;/P&gt;&lt;P&gt;so&lt;BR /&gt;do auto NAT 10.150.50.10 -&amp;gt; 193.100.200.74 for cXL 5600 (only) - and check it&lt;/P&gt;&lt;P&gt;when I try to connect 193.100.200.74 (web server) at external - not worked, not connect. I saw by logs,(by SMS) how NAT rule worked at cXL 5600, but to ended destination didnt get it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how to do it ?&lt;BR /&gt;how to get autoNat for 5600 and get answer for 193.100.200.74 (web server) ?&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;</description>
    <pubDate>Wed, 03 Mar 2021 21:09:53 GMT</pubDate>
    <dc:creator>dkurochkin</dc:creator>
    <dc:date>2021-03-03T21:09:53Z</dc:date>
    <item>
      <title>Natting IP address for not DC network</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Natting-IP-address-for-not-DC-network/m-p/112411#M21158</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="check_56_58.png" style="width: 990px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10744iE80388031A618203/image-size/large?v=v2&amp;amp;px=999" role="button" title="check_56_58.png" alt="check_56_58.png" /&gt;&lt;/span&gt;hello&lt;/P&gt;&lt;P&gt;Need natting at fw-1 some hosts which is in aubnet connected to fw-2&lt;/P&gt;&lt;P&gt;we have ClusterXL 5800 gw and some direct connection networks for him and NAT realized here&lt;/P&gt;&lt;P&gt;so&lt;BR /&gt;we have ClusterXL 5600 gw and want to realized NAT here for all networks behind clusterXL 5800 (do it for more secure ;0)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cXL 5800 conected with cXL 5600 by 172.19.19.0/29 network&lt;/P&gt;&lt;P&gt;and cXL 5600 have route to networks behind clusterXL 5800&lt;/P&gt;&lt;P&gt;when, for example, at 5600 ping 10.150.50.10 - success, when ping hpe.com - success&lt;BR /&gt;thus 5600 have conncect for internal and external networks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;# 10.150.50.10 -&amp;gt; 193.100.200.74 (web server)&lt;/P&gt;&lt;P&gt;so&lt;BR /&gt;do auto NAT 10.150.50.10 -&amp;gt; 193.100.200.74 for cXL 5800 (only) - and check it&lt;/P&gt;&lt;P&gt;All ok, its works&lt;/P&gt;&lt;P&gt;so&lt;BR /&gt;do auto NAT 10.150.50.10 -&amp;gt; 193.100.200.74 for cXL 5600 (only) - and check it&lt;/P&gt;&lt;P&gt;when I try to connect 193.100.200.74 (web server) at external - not worked, not connect. I saw by logs,(by SMS) how NAT rule worked at cXL 5600, but to ended destination didnt get it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;how to do it ?&lt;BR /&gt;how to get autoNat for 5600 and get answer for 193.100.200.74 (web server) ?&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 21:09:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Natting-IP-address-for-not-DC-network/m-p/112411#M21158</guid>
      <dc:creator>dkurochkin</dc:creator>
      <dc:date>2021-03-03T21:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: Natting IP address for not DC network</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Natting-IP-address-for-not-DC-network/m-p/112591#M21178</link>
      <description>&lt;P&gt;The only thing that's clear is that you have a subnet (10.150.50.0/24) behind a 5800.&lt;BR /&gt;From your 5800, there is a line that forks in two directions:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A line that goes to the 5600 (presumably the 172.19.19/0 subnet)&lt;/LI&gt;
&lt;LI&gt;A line that goes straight to the "noname border gateway."&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;What is the precise connectivity here?&lt;BR /&gt;Is this a single interface with two IPs (only way this can logically work)?&lt;BR /&gt;Is this two different interfaces?&lt;BR /&gt;Are the 5600, 5800, and the noname border gateway actually connected to the same physical switch and on the same logical network?&lt;BR /&gt;Please clarify this situation.&lt;/P&gt;
&lt;P&gt;If only your 5600 is on the same subnet as the noname border gateway then it must ultimately do the NAT between private and public address space.&lt;BR /&gt;The 5800 cannot do that in this case.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Mar 2021 01:22:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Natting-IP-address-for-not-DC-network/m-p/112591#M21178</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-06T01:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Natting IP address for not DC network</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Natting-IP-address-for-not-DC-network/m-p/112748#M21194</link>
      <description>&lt;P&gt;I'm so sorry gor my bad draw&lt;/P&gt;&lt;P&gt;of course 5800 have more than 1 interface&lt;/P&gt;&lt;P&gt;for example, bond1.3070 - for 5600, and bond1.3089 for noname router&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;how it work now:&lt;BR /&gt;internal network by 5800, natting by 5800 and go to internet by 5800 trough noname border router&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what i want:&lt;BR /&gt;internal network by 5800, natting by 5600 and go to internet by 5600 trough noname border router, at 5800 remove interface bond1.3089 for noname router&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 17:45:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Natting-IP-address-for-not-DC-network/m-p/112748#M21194</guid>
      <dc:creator>dkurochkin</dc:creator>
      <dc:date>2021-03-08T17:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: Natting IP address for not DC network</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Natting-IP-address-for-not-DC-network/m-p/112754#M21197</link>
      <description>&lt;P&gt;I don’t see why that wouldn’t work provided you:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Change the default route on the 5800 to point to the 5600.&lt;/LI&gt;
&lt;LI&gt;Actually remove the VLAN (not just disable it) for the no name router from the 5800.&lt;/LI&gt;
&lt;LI&gt;Configure NAT only on the 5600, not the 5800.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If it’s not working, I’d run tcpdump on the 5800 and 5600 to see that the traffic is being routed out the correct interface and the NAT is happening at the right place.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 19:16:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Natting-IP-address-for-not-DC-network/m-p/112754#M21197</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-08T19:16:45Z</dc:date>
    </item>
  </channel>
</rss>

