<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Source NAT subnet and actual in same Encryption domain in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-Source-NAT-subnet-and-actual-in-same-Encryption-domain/m-p/16779#M2810</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Checkmates!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question&amp;nbsp;regarding VPN. On a VSX platform in a single domain on a single Virtual System I am trying to establish a VPN, where we are source NAT'ing in our end and they are aswell.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can establish&amp;nbsp;Phase 1 and 2 without issues and I can tell that the VPN is establishing with the correct NAT'ed subnet, yet we're not able to send traffic through.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this cause an issue if we have both the actual subnet and NAT'ed subnet in the VPN domain manually defined on the VS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kind regards&lt;/P&gt;&lt;P&gt;hope you can help.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Aug 2018 10:42:32 GMT</pubDate>
    <dc:creator>Markus_Hoyer1</dc:creator>
    <dc:date>2018-08-07T10:42:32Z</dc:date>
    <item>
      <title>VPN Source NAT subnet and actual in same Encryption domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Source-NAT-subnet-and-actual-in-same-Encryption-domain/m-p/16779#M2810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Checkmates!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question&amp;nbsp;regarding VPN. On a VSX platform in a single domain on a single Virtual System I am trying to establish a VPN, where we are source NAT'ing in our end and they are aswell.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can establish&amp;nbsp;Phase 1 and 2 without issues and I can tell that the VPN is establishing with the correct NAT'ed subnet, yet we're not able to send traffic through.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this cause an issue if we have both the actual subnet and NAT'ed subnet in the VPN domain manually defined on the VS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kind regards&lt;/P&gt;&lt;P&gt;hope you can help.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Aug 2018 10:42:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Source-NAT-subnet-and-actual-in-same-Encryption-domain/m-p/16779#M2810</guid>
      <dc:creator>Markus_Hoyer1</dc:creator>
      <dc:date>2018-08-07T10:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Source NAT subnet and actual in same Encryption domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Source-NAT-subnet-and-actual-in-same-Encryption-domain/m-p/16780#M2811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do logs say? Drop on last rule or something else? How is your rule set up?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Aug 2018 12:03:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Source-NAT-subnet-and-actual-in-same-Encryption-domain/m-p/16780#M2811</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-08-07T12:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Source NAT subnet and actual in same Encryption domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Source-NAT-subnet-and-actual-in-same-Encryption-domain/m-p/16781#M2812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have two manual NAT rules created for egress and ingress of the traffic coming from or destined to the VPN peer?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Aug 2018 20:31:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Source-NAT-subnet-and-actual-in-same-Encryption-domain/m-p/16781#M2812</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-08-07T20:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Source NAT subnet and actual in same Encryption domain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Source-NAT-subnet-and-actual-in-same-Encryption-domain/m-p/16782#M2813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes we have two manual NAT's for both egress and ingress.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yesterday in the maintenance&amp;nbsp;window we got the VPN up and running, we didn't do any changes, the issue was the ruleset in the other end.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The logs translated correctly as intended.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was just curious towards the design of the Checkpoint whether it might cause an issue having both the actual and NAT'ed subnet in the encryption domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you both for your replies &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2018 09:24:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Source-NAT-subnet-and-actual-in-same-Encryption-domain/m-p/16782#M2813</guid>
      <dc:creator>Markus_Hoyer1</dc:creator>
      <dc:date>2018-08-08T09:24:49Z</dc:date>
    </item>
  </channel>
</rss>

