<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with NAT and ISP in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-NAT-and-ISP/m-p/184207#M30684</link>
    <description>&lt;P&gt;I recommend engaging the TAC here: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jun 2023 19:16:52 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-06-16T19:16:52Z</dc:date>
    <item>
      <title>Problem with NAT and ISP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-NAT-and-ISP/m-p/183941#M30640</link>
      <description>&lt;P&gt;Good afternoon.&lt;BR /&gt;&lt;BR /&gt;We have ISP1 and ISP2 configured on the security gateway.&lt;BR /&gt;We also have NAT rules configured.&lt;BR /&gt;ISP1 uses the external address of the Security Gateway. And ISP2 uses 4 addresses: one external from the Security Gateway and 3 not on the gateway. Proxy ARP is configured for these 3 external addresses.&lt;/P&gt;&lt;P&gt;For some reason, with problems with one ISP, encountered the following situation:&lt;BR /&gt;1. The default route changes correctly (switches to the gateway of the desired ISP).&lt;BR /&gt;2. NAT rules are not working. The NAT rule above (E.g.: ISP1 was working and become unreachable, then the route is changed to ISP2. BUT the NAT rule works for ISP1 because it is upstream to ISP2).&lt;/P&gt;&lt;P&gt;To solve the NAT problem, we modified the NAT rules according to sk174197. We added RNGX objects. Here is how it worked: we had the same rules with RNGX1 and the rule was repeated for RNGX2.&lt;BR /&gt;NAT started working correctly (the addresses were hiding behind the right address, according to the automatic rule). But for some reason NAT didn't work for one subnet (there was no NAT in the logs, the checkpoint traffic let through) and the servers on that subnet didn't have Internet access.&lt;/P&gt;&lt;P&gt;Can you tell me what could be the problem?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 08:03:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-NAT-and-ISP/m-p/183941#M30640</guid>
      <dc:creator>Oliver_222</dc:creator>
      <dc:date>2023-06-14T08:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAT and ISP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-NAT-and-ISP/m-p/184000#M30652</link>
      <description>&lt;P&gt;Version/JHF of the gateway in question? (Or if it's an SMB, the firmware version)&lt;BR /&gt;Please explain what is meant by "&lt;SPAN&gt;the NAT rule works for ISP1 because it is upstream to ISP2)."&lt;BR /&gt;Also, showing the exact rules used would be helpful.&lt;BR /&gt;Can you also provide a simple network diagram?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2023 18:23:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-NAT-and-ISP/m-p/184000#M30652</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-14T18:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAT and ISP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-NAT-and-ISP/m-p/184183#M30683</link>
      <description>&lt;P&gt;R81.10 JHF Take 55&lt;BR /&gt;3800 Appliance.&lt;BR /&gt;When we shut down one ISP, the NAT rule worked the same and users and servers had no access to the internet. But when we raised ISP2 higher than ISP1, the NAT rule worked for ISP2 and there was internet access (picture 1).&lt;BR /&gt;Setting NAT with RNGX (picture 2) - in this case everything worked correctly (as I think), the default route was changed to another provider, in the logs addresses were hidden behind the same provider. But only the subnet 172.16.0.0/24 didn't have Internet working.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21454i29CB1A59E2DD61EC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21455i57D31BA058A61555/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21456i03F14F7025FF0902/image-size/medium?v=v2&amp;amp;px=400" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 11:43:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-NAT-and-ISP/m-p/184183#M30683</guid>
      <dc:creator>Oliver_222</dc:creator>
      <dc:date>2023-06-16T11:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAT and ISP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-NAT-and-ISP/m-p/184207#M30684</link>
      <description>&lt;P&gt;I recommend engaging the TAC here: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 19:16:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-NAT-and-ISP/m-p/184207#M30684</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-16T19:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAT and ISP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-NAT-and-ISP/m-p/184904#M30802</link>
      <description>&lt;P&gt;did you fix the problem? i'm interested in a similar scenario&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 08:34:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-NAT-and-ISP/m-p/184904#M30802</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2023-06-27T08:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with NAT and ISP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Problem-with-NAT-and-ISP/m-p/184908#M30803</link>
      <description>&lt;P&gt;We are currently investigating the problem together with the TAC&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jun 2023 08:53:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Problem-with-NAT-and-ISP/m-p/184908#M30803</guid>
      <dc:creator>Oliver_222</dc:creator>
      <dc:date>2023-06-27T08:53:45Z</dc:date>
    </item>
  </channel>
</rss>

