<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT problem in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210665#M34880</link>
    <description>&lt;P&gt;I have a suggestion...run ip r g command when it works and when it does not and compare.&lt;/P&gt;
&lt;P&gt;if dst is 10.10.10.10, just run from expert ip r g 10.10.10.10&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 08 Apr 2024 11:07:38 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-04-08T11:07:38Z</dc:date>
    <item>
      <title>NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210592#M34867</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;I have two 3000 checkpoint firewall and two sites&lt;/P&gt;&lt;P&gt;Site A&lt;BR /&gt;LAN site A is 192.168.1.0/24 and default gateway is 192.168.1.254&amp;nbsp; with a interface on Checkpoint.&lt;BR /&gt;With the following&amp;nbsp;&lt;BR /&gt;IPv4 static route 10.20.20.0/24 to 192.168.1.1&lt;/P&gt;&lt;P&gt;Its IPVPN so they both sides are Trunked on Cisco switch&lt;BR /&gt;Cisco switch does not have any IP route&lt;/P&gt;&lt;P&gt;Site B&lt;BR /&gt;LAN site B is 10.20.20.0/24 and default gateway 10.20.20.254 same config&lt;BR /&gt;With the following&amp;nbsp;&lt;BR /&gt;IPv4 static route 192.168.1.0 to 10.20.20.1&lt;/P&gt;&lt;P&gt;I`m able to ping each default-gateway and the gateway of each jump.&amp;nbsp;&lt;BR /&gt;But when I try to ping a client 10.20.20.x to 192.168.1.x they cant reach each other unless I create a route print.&lt;/P&gt;&lt;P&gt;I have tried several NAT configuration but not really sure what would be the right on on each side.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Sat, 06 Apr 2024 11:27:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210592#M34867</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2024-04-06T11:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210613#M34871</link>
      <description>&lt;P&gt;Please provide a diagram and mention versions in use&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2024 13:23:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210613#M34871</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-04-07T13:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210615#M34872</link>
      <description>&lt;P&gt;I second what Val said. If you send us basic diagram (paint would do as well), it would give us better idea, so we can help you more.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2024 14:53:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210615#M34872</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-07T14:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210650#M34876</link>
      <description>&lt;P&gt;R81.20 and&amp;nbsp;&lt;SPAN&gt;R80.30&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="diagram.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25190i3D159EBA70182FBC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="diagram.PNG" alt="diagram.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 08:30:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210650#M34876</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2024-04-08T08:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210652#M34877</link>
      <description>&lt;P&gt;Check your logs, I bet you'll see lots of out-of-state drops. If you do, the issue is asymmetric routing. Your C2S packets go from the client to their local gateway and over to the server via the Cisco devices, then the S2C packet goes to the server local gateway that never saw the C2S packet, hence doesn't have the connection in its tables and is dropping it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If that's the case, I suggest that the IPVPN be moved to dedicated interfaces/subnets rather than sharing the client subnet, so all packets must traverse both gateways in both directions.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 08:48:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210652#M34877</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-04-08T08:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210656#M34878</link>
      <description>&lt;P&gt;Forget the IPVPN, that was my mistake. its just Layer 3 Routing, Im able to ping when i do static route on the computers on each side. I dont see any drop of packets i can see when i ping each side of the firewalls&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 09:07:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210656#M34878</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2024-04-08T09:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210661#M34879</link>
      <description>&lt;P&gt;Dont wanna change the LAYER 3 routing, is there a way for me to do this simple? I cant have static routes on every hosts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 10:55:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210661#M34879</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2024-04-08T10:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210665#M34880</link>
      <description>&lt;P&gt;I have a suggestion...run ip r g command when it works and when it does not and compare.&lt;/P&gt;
&lt;P&gt;if dst is 10.10.10.10, just run from expert ip r g 10.10.10.10&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 11:07:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210665#M34880</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-08T11:07:38Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210673#M34881</link>
      <description>&lt;P&gt;I should work with the right NAT configuration right?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 12:15:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210673#M34881</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2024-04-08T12:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210676#M34882</link>
      <description>&lt;P&gt;Thats always been key IT word...SHOULD lol. Yes, it should work, agree, but if it does not, maybe if you can send how you configure the NAT, we can verify.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 12:19:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210676#M34882</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-08T12:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210690#M34886</link>
      <description>&lt;P&gt;Site A&lt;/P&gt;&lt;P&gt;src.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;dst.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;trans-src.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;trans-dst.&lt;BR /&gt;192.168.1.0/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10.20.20.0/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Original&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10.20.20.254 - static&lt;BR /&gt;10.20.20.0/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.1.0/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 10.20.20.254-static&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Original&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Site B&lt;BR /&gt;sr.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;dst.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;trans-src&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;trans-dst&lt;BR /&gt;10.20.20.0/24 192.186.1.0/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Orginal&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.1.254 - static&lt;BR /&gt;192.168.1.0/24 10.20.20.0/24&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.1.254-static&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Orignal&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 13:01:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210690#M34886</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2024-04-08T13:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210764#M34901</link>
      <description>&lt;P&gt;Just to give quick update on this,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/108446"&gt;@Phoenix&lt;/a&gt;&amp;nbsp;and I did remote session today and I am also fairly sure something with nat rule is missing here, so once thats sorted out, Im positive it will work.&lt;/P&gt;
&lt;P&gt;Let me know when you are free Tuesday and we can do another zoom.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 02:17:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210764#M34901</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-09T02:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210825#M34914</link>
      <description>&lt;P&gt;Unable to do that right now, whats the best workaround?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 12:02:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210825#M34914</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2024-04-09T12:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210854#M34921</link>
      <description>&lt;P&gt;Ah, ok, I see what we missed yesterday, good job!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 13:28:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210854#M34921</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-09T13:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210871#M34922</link>
      <description>&lt;P&gt;You can potentially kludge it by&amp;nbsp; configuring on the site A gateway a hideNAT for site A subnet behind the site A gateway for traffic to site B and vice-versa.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 15:02:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210871#M34922</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-04-09T15:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: NAT problem</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210873#M34923</link>
      <description>&lt;P&gt;That may work.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 16:01:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-problem/m-p/210873#M34923</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-09T16:01:50Z</dc:date>
    </item>
  </channel>
</rss>

