<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R80.10 - Hide behind many question in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3828#M256</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Started loving R80.10, but still need to explore more.&lt;/P&gt;&lt;P&gt;Have a question :Whether R80.10 supports Hide behind many ip address (like range or pool of address), or still we need to divide the sources if the scaling crosses 50k ports.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Jun 2017 20:03:06 GMT</pubDate>
    <dc:creator>VENKAT_S_P</dc:creator>
    <dc:date>2017-06-27T20:03:06Z</dc:date>
    <item>
      <title>R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3828#M256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Started loving R80.10, but still need to explore more.&lt;/P&gt;&lt;P&gt;Have a question :Whether R80.10 supports Hide behind many ip address (like range or pool of address), or still we need to divide the sources if the scaling crosses 50k ports.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jun 2017 20:03:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3828#M256</guid>
      <dc:creator>VENKAT_S_P</dc:creator>
      <dc:date>2017-06-27T20:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3829#M257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's a little more complicated than just 50,000 connections going to the same destination, as described here:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103656&amp;amp;partition=General&amp;amp;product=CoreXL%22" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103656&amp;amp;partition=General&amp;amp;product=CoreXL%22"&gt;Dynamic NAT port allocation feature&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In general, though, you can only specify one address as the source IP for a HIDE address, which should still also apply to R80.10.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jun 2017 20:51:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3829#M257</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-06-27T20:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3830#M258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;probably in future releases.&lt;BR /&gt;Thanks Dameon for prompt reply.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jun 2017 22:43:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3830#M258</guid>
      <dc:creator>VENKAT_S_P</dc:creator>
      <dc:date>2017-06-27T22:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3831#M259</link>
      <description>&lt;P&gt;Sorry to come in so late on this thread, but what I would call "many-to-fewer" hide NAT is most definitely possible via manual NAT rules and has been around since R75.&amp;nbsp; It is not really documented but it definitely does work, subject to the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) Manual NAT must be used&lt;/P&gt;
&lt;P&gt;2) In Original Source put the inside network object to hide&lt;/P&gt;
&lt;P&gt;3) Translated Source of the manual NAT rule MUST be a IP Address Range object (a network object will not work), configured with the routable range of "fewer" addresses to hide behind&lt;/P&gt;
&lt;P&gt;4) By default after adding the range object in Translated Source it will be set to static, right-click and force it to Hide&lt;/P&gt;
&lt;P&gt;5) Because you are almost certainly plucking these "fewer" addresses from your routable range of addresses located on the dirty subnet between the firewall's external interface and the perimeter router, you must add manual static proxy ARPs for ALL addresses in the "fewer" range.&amp;nbsp; Failing to add static proxy ARPs for every address in the "fewer" range will cause random-looking failures for some internal hosts and not others.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are running R80.10 gateway though check out &lt;A style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114395&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener"&gt;sk114395: Automatic creation of Proxy ARP for Manual NAT rules on Security Gateway R80.10&lt;/A&gt;.&amp;nbsp; &lt;EM&gt;&lt;STRONG&gt;Edit: I recently saw a many-to-fewer NAT setup utilizing this new Auto Proxy ARP feature on a R80.10 gateway and it worked great!&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I recall the selection of which "fewer" IP address to hide a particular internal host behind depends on that host's IP address.&amp;nbsp; So if we are using 192.168.1.0/24 internally and hiding behind 129.82.102.32 - 129.82.102.35, internal host 192.168.1.3 might draw 129.82.102.33 for all its connections while 192.168.1.134 might draw 129.82.102.35 for all its connections.&amp;nbsp; I don't think the "fewer" address associated to an internal IP will ever change though (unless the "fewer" IP range changes) so there must be some kind of static hash function at work here.&amp;nbsp; &lt;STRONG&gt;Edit: In R82 it is possible to configure a "fewer" address such that it is always assigned to the same "many" address.&lt;/STRONG&gt; This behavior is mentioned here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105302&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener"&gt;sk105302: Traffic NATed behind an Address Range object is always NATed behind the same IP address&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The even distribution of internal addresses to external "fewer" addresses will never be perfect of course, but will allow one to go well beyond the 50k limit of concurrent connections to the same destination being hidden by a single hide NAT rule.&amp;nbsp; I just tried it in my R80.10 lab for grins and this setup still works&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--&lt;BR /&gt;My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt;now available via &lt;A href="http://maxpowerfirewalls.com" target="_blank" rel="noopener"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 19:41:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3831#M259</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-11-02T19:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3832#M260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot Tim, this really helps.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Sep 2017 15:17:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3832#M260</guid>
      <dc:creator>VENKAT_S_P</dc:creator>
      <dc:date>2017-09-15T15:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3833#M261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a screenshot from the Second Edition of my book Max Power that nicely summarizes how to set this up:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="61249" alt="How to set up many to fewer Hide NAT" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61249_fewer.jpg" style="width: 620px; height: 451px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My Book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; Second Edition Coming Soon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Dec 2017 15:16:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3833#M261</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-12-06T15:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3834#M262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cheers Tim, can confirm this works great on a 41K on R76SP.50.&lt;/P&gt;&lt;P&gt;This is with the Dynamic Port allocation turned on (which is default), which we have been told to run off by support as it's causing us issues.&lt;/P&gt;&lt;P&gt;We needed to add a couple of /16s as Hide NAT addresses and this has saved us loads of time as we haven't had to create 500+ objects and NAT rules.&lt;/P&gt;&lt;P&gt;Hopefully it still works OK when we turn off Dynamic NAT port allocation, will let you know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Feb 2018 12:03:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3834#M262</guid>
      <dc:creator>Jennifer_Wilson</dc:creator>
      <dc:date>2018-02-02T12:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3835#M263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not CheckPoint employee, is there any chance that I can buy your book?&lt;/P&gt;&lt;P&gt;I need to configure hide NAT using public IP pool for a customer. Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;AZH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Feb 2018 12:41:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3835#M263</guid>
      <dc:creator>Zaw_Hein_Aung</dc:creator>
      <dc:date>2018-02-25T12:41:34Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3836#M264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zaw,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the steps you need to set up a many-to-fewer NAT are contained earlier in this thread, however if you still want to buy the book head to maxpowerfirewalls.com to look at the different PDF and/or hardcopy purchase options.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 13:07:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3836#M264</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-02-26T13:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3837#M265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just confirming this is still working fine after turning Dynamic NAT off (also after having installed Hotfixes 002 and 050 for CCP issues causing blades and chassis to failover).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2018 16:35:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3837#M265</guid>
      <dc:creator>Jennifer_Wilson</dc:creator>
      <dc:date>2018-03-13T16:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3838#M266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just bought the Edition2 of the book and i highly recommend this, specially if you are running R80+, lots if insightful tips covered and best practices&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2018 21:50:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3838#M266</guid>
      <dc:creator>Yuvy_Ruhee</dc:creator>
      <dc:date>2018-05-30T21:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3839#M267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Timothy. I was presented with this case today and your answer was very helpful! Still, I'm having trouble with the proxy ARP configuration, since I have to do it manually.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created an address range object and configured the NAT rule accordingly, but I can't seem to add the proper Proxy ARP entry for source NAT, since I'm having trouble recognizing which would be the advertised IP and the real IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please elaborate on this? Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Sep 2018 21:24:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3839#M267</guid>
      <dc:creator>Carlos_Machado1</dc:creator>
      <dc:date>2018-09-06T21:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3840#M268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Precisely how the Proxy ARPs are added will depend on whether ClusterXL is in use and some other factors such as hardware platform.&amp;nbsp; Please check out the fairly lengthy &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30197&amp;amp;partition=Advanced&amp;amp;product=ClusterXL," style="max-width: 840px;"&gt;sk30197: Configuring &lt;STRONG&gt;Proxy&lt;/STRONG&gt; &lt;STRONG&gt;ARP&lt;/STRONG&gt; for Manual NAT&lt;/A&gt; for the correct steps to use in your specific environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2018 12:41:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3840#M268</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-09-07T12:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3841#M269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tim,&lt;/P&gt;&lt;P&gt;Can you remind me if the Proxy ARP is still necessary when we are configuring manual NAT rule for hiding our encryption domain behind the IP/Range provided by the peer?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2018 14:06:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3841#M269</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-09-25T14:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3842#M270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the packets for those IPs would only arrive encrypted, proxy ARPs shouldn't be necessary.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2018 15:11:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3842#M270</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-25T15:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3843#M271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As Dameon mentioned any IP addresses being tunneled by IPSec do not need a proxy ARP (even if they are plucked from your ISP-assigned routable range or dirty subnet) as the outside destination IP address on the ESP packet is just the external IP of the firewall for which it will already automatically answer ARP requests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For NAT the only time proxy ARPs are required is when "plucking" NAT addresses from a subnet that is directly attached to the firewall itself.&amp;nbsp; In the real world this is most typically the so-called "dirty" subnet sitting between the firewall and the Internet perimeter router.&amp;nbsp; In most implementations all or at least a chunk of the ISP-assigned routable address space exists on the dirty subnet.&amp;nbsp; Any addresses plucked from that directly-attached dirty subnet for NAT will need Proxy ARP service provided by the firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However other portions of ISP-assigned space (whether they be different subnets adjacent or near to the dirty subnet, or a completely different routable subnet assigned by the ISP later when the original one was exhausted) are merely using the dirty subnet as a transit to reach the firewall and do not need Proxy ARPs as a result.&amp;nbsp; There will be static routes on the Internet perimeter router for these other routable subnets designating the firewall's outside address as the next hop, so there is no need for the Internet perimeter router to ARP for the destination IP addresses in those packets.&amp;nbsp; Proxy ARP is usually just for the benefit of the Internet perimeter router, regardless of whether your organization owns it or your ISP manages it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2018 16:12:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3843#M271</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-09-25T16:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3844#M272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;I typically break down the public range and use it's small subnet between gateways/clusters and the ISP router. The other subnets of the public range are forwarded from the router to the external IP of the gateway or cluster for either use in DMZ(s) or NAT. This does remove the need for the Proxy ARP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2018 16:23:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3844#M272</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-09-25T16:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3845#M273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm in the assumption that Proxy ARP is not needed when you translate the source address only. The router will learn the MAC address from the initial packet and everything will work. ( I'm never been in a situation where the return packet exceeded the time-out of the mac table. )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm only configuring Proxy ARP when doing a Destination NAT since the first packet will come from a router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a customer doesn't like proxy arp, you can always ask your ISP to put host routes to your VIP ip address for your "plucked" IP's.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2018 14:05:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3845#M273</guid>
      <dc:creator>Kristof_Vermael</dc:creator>
      <dc:date>2018-11-26T14:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3846#M274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To update this old thread, looks like Check Point has now formally documented this many-to-fewer NAT setup here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk142833&amp;amp;partition=General&amp;amp;product=SmartConsole" style="max-width: 840px;" rel="nofollow noopener noreferrer" target="_blank"&gt;sk142833: How to create manual NAT rules in &lt;STRONG&gt;Many-To-Few&lt;/STRONG&gt; mode&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also it has been officially confirmed by Check Point in the thread below that Hide NAT can support more than 50k concurrent connections through the same single Hide NAT address, as long as the destination IP addresses are unique.&amp;nbsp; Never got an answer as to when exactly that changed (I know for a fact that it didn't used to be that way, but that was a VERY long time ago) but I suspect it was version R75:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/message/32343" target="_blank"&gt;https://community.checkpoint.com/message/32343&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;--&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;CheckMates Break Out Sessions Speaker&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;CPX 2019 Las Vegas &amp;amp; Vienna - Tuesday@13:30&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 08:56:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3846#M274</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-06-21T08:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 - Hide behind many question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3847#M275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the NAT space have to be contiguous IP space?&amp;nbsp; Could a network group be used with non contiguous IP space?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2019 15:51:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-Hide-behind-many-question/m-p/3847#M275</guid>
      <dc:creator>Bill_Ng</dc:creator>
      <dc:date>2019-01-31T15:51:41Z</dc:date>
    </item>
  </channel>
</rss>

