<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: We want to configure Destination NAT but it is not in the same subnet of the ingress interface. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/We-want-to-configure-Destination-NAT-but-it-is-not-in-the-same/m-p/202473#M33702</link>
    <description>&lt;P&gt;You can configure NAT rules this way, but other parts of the network may need to be configured to support it.&lt;/P&gt;
&lt;P&gt;What is the default route for your clients here?&lt;BR /&gt;Will it direct traffic from 172.20.112.80 to your gateway?&lt;BR /&gt;If not, you will need to fix that.&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jan 2024 14:04:01 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-01-08T14:04:01Z</dc:date>
    <item>
      <title>We want to configure Destination NAT but it is not in the same subnet of the ingress interface.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/We-want-to-configure-Destination-NAT-but-it-is-not-in-the-same/m-p/202419#M33697</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Hi Everyone,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I am sort of stuck in a problem with Destination NAT on a different subnet than the egress interface. To further complicate matters, The destination NAT IP subnet is also part of another interface subnet which is not relevant to this flow. I have made a rough diagram to make it a bit more clear.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;* We want our client machines to connect to a destination NAT IP 172.20.112.80 which will translate to 163.116.128.80. The traffic will enter through eth2-01 and exit through eth2-02.611. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;* Issue is that the NAT IP 172.20.112.80 is on a different network than the IP of the Ingress interface (172.20.128.65/25) &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;* Further to this there is also an interface on the firewall eth2-02.628 which is connected to the network 172.20.112.0/24. &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;*&amp;nbsp; our users need to connect to the NAT IP 172.20.112.80, it should enter through eth2-01 and exit through eth2-02.26.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Appreciate you taking the time to read through. Thanks in advance.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 08 Jan 2024 04:29:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/We-want-to-configure-Destination-NAT-but-it-is-not-in-the-same/m-p/202419#M33697</guid>
      <dc:creator>shopworld</dc:creator>
      <dc:date>2024-01-08T04:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: We want to configure Destination NAT but it is not in the same subnet of the ingress interface.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/We-want-to-configure-Destination-NAT-but-it-is-not-in-the-same/m-p/202473#M33702</link>
      <description>&lt;P&gt;You can configure NAT rules this way, but other parts of the network may need to be configured to support it.&lt;/P&gt;
&lt;P&gt;What is the default route for your clients here?&lt;BR /&gt;Will it direct traffic from 172.20.112.80 to your gateway?&lt;BR /&gt;If not, you will need to fix that.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 14:04:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/We-want-to-configure-Destination-NAT-but-it-is-not-in-the-same/m-p/202473#M33702</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-01-08T14:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: We want to configure Destination NAT but it is not in the same subnet of the ingress interface.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/We-want-to-configure-Destination-NAT-but-it-is-not-in-the-same/m-p/202478#M33704</link>
      <description>&lt;P&gt;You can probably make this work, but you are going "against the grain" of normal IP routing.&lt;/P&gt;
&lt;P&gt;1) First off, under Global Properties, NAT verify that "translate destination on the client side" is checked for both automatic and manual NAT (this the default).&amp;nbsp; DO NOT EVEN THINK ABOUT UNCHECKING ANY BOXES ON THIS SCREEN.&lt;/P&gt;
&lt;P&gt;2) Next, add a static route on the firewall for&amp;nbsp;&lt;SPAN&gt;172.20.112.80/32 to a next hop router reachable through the&amp;nbsp;eth2-02.611 interface.&amp;nbsp; You cannot just specify the interface name, you must specify a nexthop router address leading to eth2-02.611.&amp;nbsp; This /32 is more specific and will override your existing directly attached /24 route to&amp;nbsp;172.20.112.0/24.&amp;nbsp; Note that the "real"&amp;nbsp;172.20.112.80/32 reachable through&amp;nbsp;eth2-02.628 will no longer be accessible by any traffic traversing the firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3) Check the topology of your firewall/cluster for interface for&amp;nbsp;eth2-02.611, if not using "network defined by routes" you will need to add&amp;nbsp;172.20.112.80/32 to the anti-spoofing definition for this interface.&amp;nbsp; You do NOT need to remove&amp;nbsp;172.20.112.80/32 from the topology of interface&amp;nbsp;eth2-02.628.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;4) You will need to ensure that your surrounding network will deliver traffic bound to&amp;nbsp;&lt;SPAN&gt;172.20.112.80/32 to the firewall on eth2-01; the firewall cannot force/spoof this with proxy ARP or somesuch in your scenario.&amp;nbsp; This may involve static&amp;nbsp;172.20.112.80/32 routes added directly on user workstations, or adding a static&amp;nbsp;172.20.112.80/32 route on a router(s) in your network.&amp;nbsp; If the firewall is already the default route for these user workstations you should not need to deal with this.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;5) Next step will be a manual NAT rule.&amp;nbsp; Because you are attempting to pluck the&amp;nbsp;172.20.112.80/32 address from an existing, real&amp;nbsp; /24 subnet and send it somewhere else, there is a danger of asymmetric routing breaking things.&amp;nbsp; For this reason I'd suggest both a source Hide NAT behind the egress firewall interface&amp;nbsp;eth2-02.611 as well as the destination static NAT, to ensure replies come back symmetrically to the firewall.&amp;nbsp; Keep in mind that if you do this connections can only be initiated outbound by the workstations and not the other way around; also this Hide NAT part may not be necessary depending&amp;nbsp;on your network.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Manual NAT rule will look something like this:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;Osrc=(initiating workstation subnet)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;ODst=172.20.112.80/32 &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;OSrv = Any&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;Tsrc=Firewall Object (Force Hide)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;TDst=163.116.128.80/32 (Static)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;Tsrc=Original&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;GW=(relevant gateway)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;6) In your Access Control policy ensure you have a rule accepting the traffic, keep in mind you should always reference the pre-NAT IP addresses here, so:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;src=&amp;nbsp;(initiating workstation subnets)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;Dst =&amp;nbsp;172.20.112.80/32&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;Service=whatever&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;Action=Accept&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;Track=Log (make sure "Connection" logging is set in advanced properties so you get proper NAT logging)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 14:20:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/We-want-to-configure-Destination-NAT-but-it-is-not-in-the-same/m-p/202478#M33704</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-01-08T14:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: We want to configure Destination NAT but it is not in the same subnet of the ingress interface.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/We-want-to-configure-Destination-NAT-but-it-is-not-in-the-same/m-p/202537#M33715</link>
      <description>&lt;P&gt;The default gateway for the clients is another L3 switch before the packet makes its way to the firewall.&lt;/P&gt;&lt;P&gt;Yes, it will direct the traffic to the Checkpoint gateway and I can see it in the logs.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 21:09:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/We-want-to-configure-Destination-NAT-but-it-is-not-in-the-same/m-p/202537#M33715</guid>
      <dc:creator>shopworld</dc:creator>
      <dc:date>2024-01-08T21:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: We want to configure Destination NAT but it is not in the same subnet of the ingress interface.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/We-want-to-configure-Destination-NAT-but-it-is-not-in-the-same/m-p/202539#M33717</link>
      <description>&lt;P&gt;Thank you. I'll try this in the next couple of days and report back.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 21:12:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/We-want-to-configure-Destination-NAT-but-it-is-not-in-the-same/m-p/202539#M33717</guid>
      <dc:creator>shopworld</dc:creator>
      <dc:date>2024-01-08T21:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: We want to configure Destination NAT but it is not in the same subnet of the ingress interface.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/We-want-to-configure-Destination-NAT-but-it-is-not-in-the-same/m-p/202788#M33749</link>
      <description>&lt;P&gt;Thank you so much. That worked really well. The reason we did this was because we had an old proxy server that we are going to decomission and point all servers to netskope. But changing proxy address on each server would have impacted our deadlines, so the easy approach was to NAT the old proxy IP and redirect traffic to the new netskope IP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 05:02:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/We-want-to-configure-Destination-NAT-but-it-is-not-in-the-same/m-p/202788#M33749</guid>
      <dc:creator>shopworld</dc:creator>
      <dc:date>2024-01-11T05:02:03Z</dc:date>
    </item>
  </channel>
</rss>

