<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT46 for IPv6 Tunnel in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/194886#M32624</link>
    <description>&lt;P&gt;Is this a domain-based VPN or a route-based VPN?&lt;BR /&gt;Possible that might work with a route-based VPN, but I suspect this is unsupported.&lt;BR /&gt;I would open a TAC case to get confirmation: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Oct 2023 20:52:52 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-10-11T20:52:52Z</dc:date>
    <item>
      <title>NAT46 for IPv6 Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/194712#M32594</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;we use R81.10. We have already establised a IPv6 tunnel between two Gaia gateways, because we have only a public IPv6 address on our 5G contract available.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically it works fine with the tunnel, when we use IPv6 for communication. The bad thing is, that Check Point does not support IPv4 in IPv6 tunnels. That makes it nearly useless, because we have a lot applications who are not IPv6 ready - unfortunately.&lt;/P&gt;&lt;P&gt;We tried to translate the IPv4 addresses in IPv6, that we can pass the tunnel. On the peer gateway we nat the addresses from IPv6 in IPv4 addresses back. That would make IPv6 transparent for the client/server communication.&lt;/P&gt;&lt;P&gt;Client (v4/v6) --&amp;gt;| fw1 (v6) | ==(v6 Tunnel)== | fw2 (NAT64)| ---&amp;gt; Server (v4)&lt;/P&gt;&lt;P&gt;Nat46 and Nat64 works fine. On the fw1 Nat46 will executed, but the packets are not entering the tunnel. Is there a solution to prior the Nat rules before the VPN rules (Policy)? NAT66 works fine in the tunnel, but the destination IPv6 is already included in the Encryption Domain.&lt;/P&gt;&lt;P&gt;Thanks in advance,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 19:48:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/194712#M32594</guid>
      <dc:creator>StefanBauer</dc:creator>
      <dc:date>2023-10-10T19:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: NAT46 for IPv6 Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/194730#M32597</link>
      <description>&lt;P&gt;Did you happen to include in your IPv6 Encryption Domain the IPv6 version of your IPv4 addresses?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 21:07:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/194730#M32597</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-10T21:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: NAT46 for IPv6 Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/194752#M32601</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;thanks for the fast response. Yes, the IPv6 addresses are in included in the Encryption Domain. Do you have still any other idea?&lt;/P&gt;&lt;P&gt;Destination IPv4 - 192.168.1.105 (is only in normal Access Rule)&lt;/P&gt;&lt;P&gt;Destination IPv6 (NAT46) -&amp;nbsp;2003:cf:825:210::105 (is inlcuded in the Endryption Domain)&lt;/P&gt;&lt;P&gt;If i try to connect to the IPv6 address it works fine over the IPv6 tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 05:47:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/194752#M32601</guid>
      <dc:creator>StefanBauer</dc:creator>
      <dc:date>2023-10-11T05:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: NAT46 for IPv6 Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/194808#M32613</link>
      <description>&lt;P&gt;I'm not talking about the destination encryption domain, I'm talking about the source encryption domain.&lt;BR /&gt;Is the result of the NAT46 translation included in the source encryption domain?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 13:28:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/194808#M32613</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-11T13:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: NAT46 for IPv6 Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/194828#M32616</link>
      <description>&lt;P&gt;Yes, the "Xlate (NAT)" source IP address is also in the source encryption domain.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 14:27:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/194828#M32616</guid>
      <dc:creator>StefanBauer</dc:creator>
      <dc:date>2023-10-11T14:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: NAT46 for IPv6 Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/194886#M32624</link>
      <description>&lt;P&gt;Is this a domain-based VPN or a route-based VPN?&lt;BR /&gt;Possible that might work with a route-based VPN, but I suspect this is unsupported.&lt;BR /&gt;I would open a TAC case to get confirmation: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2023 20:52:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/194886#M32624</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-11T20:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: NAT46 for IPv6 Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/195116#M32674</link>
      <description>&lt;P&gt;TAC response:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I suspect that it may work with Route based VPN(VTI) but it is currently not supported per&amp;nbsp;sk163313.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;A title="https://support.checkpoint.com/results/sk/sk163313" href="https://support.checkpoint.com/results/sk/sk163313" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk163313&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 18:08:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/195116#M32674</guid>
      <dc:creator>StefanBauer</dc:creator>
      <dc:date>2023-10-13T18:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: NAT46 for IPv6 Tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/195131#M32683</link>
      <description>&lt;P&gt;That SK doesn't really say it's not supported...but it doesn't say it is, either.&lt;BR /&gt;However, trying Route-Based VPNs (if possible) seems like the only possibility.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 20:19:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT46-for-IPv6-Tunnel/m-p/195131#M32683</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-13T20:19:52Z</dc:date>
    </item>
  </channel>
</rss>

