<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to disable NAT from VIP to Gateway when trying to ping GW? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/How-to-disable-NAT-from-VIP-to-Gateway-when-trying-to-ping-GW/m-p/216740#M36076</link>
    <description>&lt;P&gt;If the standby uses the VIP, the traffic would have to be communicated through the primary (which owns the VIP).&lt;/P&gt;
&lt;P&gt;The SK I referred to modifies the behavior for all traffic on the specific gateway, whereas I believe the table.def modifications are more focused to specific types of traffic and apply to all gateways.&lt;BR /&gt;However, if you manage gateways of different versions, table.def changes need to be made multiple places.&lt;BR /&gt;They also need to be made again on an upgrade.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jun 2024 14:31:56 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-06-06T14:31:56Z</dc:date>
    <item>
      <title>How to disable NAT from VIP to Gateway when trying to ping GW?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-disable-NAT-from-VIP-to-Gateway-when-trying-to-ping-GW/m-p/216555#M36019</link>
      <description>&lt;P&gt;Hello, I need to ping from a monitoring server to our CP GW physical IP but when I checked the logs I found out that only the VIP is replying and NATed to the active GW member. When I try to ping the GW physical IP it does not work but pinging to standby members physical IP is working. Can anyone help me? Do I need to manipulate the table.def with no_hide_services_ports = { &amp;lt;0,1&amp;gt;}? Is it possible to do this change only for the monitoring servers IP address and why is standby IP not NATed?&lt;/P&gt;&lt;P&gt;It shows me XLATE Destination IP (IP from active GW member)&lt;/P&gt;&lt;P&gt;NAT Rule number 0&lt;/P&gt;&lt;P&gt;Dst Port 0&lt;/P&gt;&lt;P&gt;Src Port 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 14:48:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-disable-NAT-from-VIP-to-Gateway-when-trying-to-ping-GW/m-p/216555#M36019</guid>
      <dc:creator>Mahajem</dc:creator>
      <dc:date>2024-06-05T14:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable NAT from VIP to Gateway when trying to ping GW?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-disable-NAT-from-VIP-to-Gateway-when-trying-to-ping-GW/m-p/216636#M36055</link>
      <description>&lt;P&gt;What version/JHF is the gateways?&lt;BR /&gt;Did you also check:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk34180" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk34180&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 01:57:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-disable-NAT-from-VIP-to-Gateway-when-trying-to-ping-GW/m-p/216636#M36055</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-06T01:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable NAT from VIP to Gateway when trying to ping GW?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-disable-NAT-from-VIP-to-Gateway-when-trying-to-ping-GW/m-p/216673#M36063</link>
      <description>&lt;P&gt;R81 JHF T92, yes I also saw this sk but where are the difference between editing table.def and this workaround? And why does the standby not using the VIP?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 08:38:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-disable-NAT-from-VIP-to-Gateway-when-trying-to-ping-GW/m-p/216673#M36063</guid>
      <dc:creator>Mahajem</dc:creator>
      <dc:date>2024-06-06T08:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable NAT from VIP to Gateway when trying to ping GW?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-disable-NAT-from-VIP-to-Gateway-when-trying-to-ping-GW/m-p/216740#M36076</link>
      <description>&lt;P&gt;If the standby uses the VIP, the traffic would have to be communicated through the primary (which owns the VIP).&lt;/P&gt;
&lt;P&gt;The SK I referred to modifies the behavior for all traffic on the specific gateway, whereas I believe the table.def modifications are more focused to specific types of traffic and apply to all gateways.&lt;BR /&gt;However, if you manage gateways of different versions, table.def changes need to be made multiple places.&lt;BR /&gt;They also need to be made again on an upgrade.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 14:31:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-disable-NAT-from-VIP-to-Gateway-when-trying-to-ping-GW/m-p/216740#M36076</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-06T14:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable NAT from VIP to Gateway when trying to ping GW?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-disable-NAT-from-VIP-to-Gateway-when-trying-to-ping-GW/m-p/216742#M36078</link>
      <description>&lt;P&gt;I also have a gut feeling sk Phoneboy gave is your best option, but you can verify with TAC if there might be better option.&lt;/P&gt;
&lt;P&gt;Personally, I doubt it...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2024 14:41:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-disable-NAT-from-VIP-to-Gateway-when-trying-to-ping-GW/m-p/216742#M36078</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-06T14:41:44Z</dc:date>
    </item>
  </channel>
</rss>

