<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT Manuals and their relationship with Proxy ARP. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184242#M30689</link>
    <description>&lt;P&gt;Depends on whether the NAT IPs are in the same subnet as your interface IP or if they are in a different subnet routed directly towards the firewall.&lt;/P&gt;</description>
    <pubDate>Sun, 18 Jun 2023 23:07:34 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-06-18T23:07:34Z</dc:date>
    <item>
      <title>NAT Manuals and their relationship with Proxy ARP.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184239#M30688</link>
      <description>&lt;P&gt;Hello, everybody.&lt;/P&gt;
&lt;P&gt;Is it mandatory to always work with the "Proxy ARP" table from Gaia Portal or Gaia CLISH, for what is the NAT MANUALS, of a service publication?&lt;/P&gt;
&lt;P&gt;I have seen documentation, in which they make reference that we must work with this table, when we need to make publications to the Internet.&lt;BR /&gt;Is it strictly obligatory, to work the table?&lt;/P&gt;
&lt;P&gt;Is there a way to simply create your manual NAT rules and avoid touching the ARP proxy table?&lt;/P&gt;
&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jun 2023 20:45:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184239#M30688</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-18T20:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Manuals and their relationship with Proxy ARP.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184242#M30689</link>
      <description>&lt;P&gt;Depends on whether the NAT IPs are in the same subnet as your interface IP or if they are in a different subnet routed directly towards the firewall.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Jun 2023 23:07:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184242#M30689</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-06-18T23:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Manuals and their relationship with Proxy ARP.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184273#M30694</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I find it difficult to interpret your idea.&lt;/P&gt;
&lt;P&gt;For example, my Real IP has the segment 10.7.53.x [An IP of this segment is configured in a Firewall leg].&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The NAT IP that we have, is an IP that is "invented" that has nothing to do with the segments that are configured in the Firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then, when a publication to the Internet is required, it is "mandatory" to work with the "Proxy ARP"????&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 13:33:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184273#M30694</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-19T13:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Manuals and their relationship with Proxy ARP.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184277#M30695</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;mentioned if your Natted IP and interface IP falls in a same subnet then you will have to use proxy arp.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Its simple and understand that if machine responds to other machine from same network it broadcast the ARP to make the discovery. Similaryl if natted IP and firewall interface are from same subnet then you need to add Proxy Arp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;e.g.&lt;/P&gt;
&lt;P&gt;Original Source&amp;nbsp; IP : 1.2.3.4&lt;/P&gt;
&lt;P&gt;Firewall interface IP: 5.6.7.8&lt;/P&gt;
&lt;P&gt;natted IP : 5.6.7.9&lt;/P&gt;
&lt;P&gt;Translated Destionation ip : 172.16.1.2&lt;/P&gt;
&lt;P&gt;Then you will have to add Proxy arp for 5.6.7.9&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 13:50:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184277#M30695</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2023-06-19T13:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Manuals and their relationship with Proxy ARP.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184289#M30698</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Just so I'm clear on the idea,&lt;/P&gt;
&lt;P&gt;Here is an example:&lt;/P&gt;
&lt;P&gt;I publish a service to Internet&lt;/P&gt;
&lt;P&gt;External IP: 200.49.210.27&lt;/P&gt;
&lt;P&gt;The internal IP of the service is: 192.168.214.200&lt;/P&gt;
&lt;P&gt;The Firewall has configured in its "eth2 leg" the IP 192.168.214.5&lt;/P&gt;
&lt;P&gt;In this "example", I will need to configure the PROXY ARP?&lt;/P&gt;
&lt;P&gt;Obs: My ClusterXL has a VIP with the Public IP 200.49.210.30&lt;/P&gt;
&lt;P&gt;Cheers. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 16:07:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184289#M30698</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-19T16:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Manuals and their relationship with Proxy ARP.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184290#M30699</link>
      <description>&lt;P&gt;Assuming 200.49.210.27 and your external IP are on the same subnet, yes.&lt;BR /&gt;The main thing is ensuring the traffic gets to the gateway.&lt;/P&gt;
&lt;P&gt;While this wasn't always the case, Proxy ARPs are done are configure automatically for automatic NAT rules.&lt;BR /&gt;For manual NAT rules, in circumstances where a proxy arp is required, they must be configured manually.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 16:41:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184290#M30699</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-19T16:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Manuals and their relationship with Proxy ARP.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184291#M30700</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Is it "mandatory" that in all the Manual NAT rules that are worked in the Checkpoint, you need to work the "Proxy ARP", or this is "optional" or for "punctual cases"?&lt;/P&gt;
&lt;P&gt;My doubt is because I have a ClusterXL environment, in which I have several NAT Manuals, but I "do not see" that the previous administrator, has worked with the PROXY ARP.&lt;/P&gt;
&lt;P&gt;I consult the ARP table by CLI with "cat $FWDIR/conf/local.arp" and well, there is no result.&lt;/P&gt;
&lt;P&gt;I just wanted to clarify the theory of the NAT Manuals, in relation to the PROXY ARP, since I have pending to publish a couple of services to Internet.&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 17:07:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184291#M30700</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-19T17:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Manuals and their relationship with Proxy ARP.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184311#M30702</link>
      <description>&lt;P&gt;No it's not mandatory as routing in some cases removes the need for proxy-arp as explained above.&lt;/P&gt;
&lt;P&gt;Proxy-arp is only needed so other devices on the same subnet can reach that address which isn't the case if the interface address and NAT IP are parts of different network subnets and routing is responsible for forwarding traffic to the gateway.&lt;/P&gt;
&lt;P&gt;Focus on what technically proxy-arp is and does and less on the NAT/CP portion to gain a better understanding.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 23:39:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-Manuals-and-their-relationship-with-Proxy-ARP/m-p/184311#M30702</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-06-19T23:39:58Z</dc:date>
    </item>
  </channel>
</rss>

