<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Natting on a different subnet that is not configured on the gateway in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Natting-on-a-different-subnet-that-is-not-configured-on-the/m-p/21542#M3976</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To confirm are the /25 and /29 overlapping networks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manual NAT is one approach, proxy-arp shouldn't be required unless the NAT IP is from the same subnet as the external interface IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Jan 2019 10:23:18 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2019-01-07T10:23:18Z</dc:date>
    <item>
      <title>Natting on a different subnet that is not configured on the gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Natting-on-a-different-subnet-that-is-not-configured-on-the/m-p/21539#M3973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to do a loopback NAT on checkpoint like cisco devices where the natted subnets for the servers are of a completely subnet then the ip addresses used for public connections?&lt;/P&gt;&lt;P&gt;The external ip address on the device is a xx.xx.xx.xx/29 network and the subnet that is going to be used for natting are of xx.xx.xx.xx/25 network.&lt;/P&gt;&lt;P&gt;when i nat a server to the internet with an ip address of the same external subnet,everything is working fine as usual but when i nat it on the /25 subnet,i cant reach the gateway.&lt;/P&gt;&lt;P&gt;Is there a correct way to configure this and is this even possible on checkpoint gateways?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jan 2019 04:30:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Natting-on-a-different-subnet-that-is-not-configured-on-the/m-p/21539#M3973</guid>
      <dc:creator>Nima_Chogyal</dc:creator>
      <dc:date>2019-01-04T04:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: Natting on a different subnet that is not configured on the gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Natting-on-a-different-subnet-that-is-not-configured-on-the/m-p/21540#M3974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes the two approaches are possible, the former relies on proxy-arp the latter on routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the upstream devices routing the x.x.x.x/25 subnet towards the security gateway?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jan 2019 06:27:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Natting-on-a-different-subnet-that-is-not-configured-on-the/m-p/21540#M3974</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2019-01-04T06:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Natting on a different subnet that is not configured on the gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Natting-on-a-different-subnet-that-is-not-configured-on-the/m-p/21541#M3975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;The upstream devices has routed the /25 network to the gateways, but the external subnets of the gateways are of /29 network and the ip of the devices to be natted to the internet are of /25 subnet(publicIP).&lt;/P&gt;&lt;P&gt;I have looked into some of the sk and im not sure if the solution is to create manual NAT rules and configure proxy-arp on the cluster members.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2019 05:11:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Natting-on-a-different-subnet-that-is-not-configured-on-the/m-p/21541#M3975</guid>
      <dc:creator>Nima_Chogyal</dc:creator>
      <dc:date>2019-01-07T05:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Natting on a different subnet that is not configured on the gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Natting-on-a-different-subnet-that-is-not-configured-on-the/m-p/21542#M3976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To confirm are the /25 and /29 overlapping networks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manual NAT is one approach, proxy-arp shouldn't be required unless the NAT IP is from the same subnet as the external interface IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2019 10:23:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Natting-on-a-different-subnet-that-is-not-configured-on-the/m-p/21542#M3976</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2019-01-07T10:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: Natting on a different subnet that is not configured on the gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Natting-on-a-different-subnet-that-is-not-configured-on-the/m-p/21543#M3977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No the networks are not overlapping. Its been separated to different subnets. I tried manual nat and what i have noticed is that only the ip that is being manually natted can ping the nated public ip, others cant ping it.does this mean that the configuration is right? or is there a route issue on the router?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jan 2019 04:57:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Natting-on-a-different-subnet-that-is-not-configured-on-the/m-p/21543#M3977</guid>
      <dc:creator>Nima_Chogyal</dc:creator>
      <dc:date>2019-01-25T04:57:20Z</dc:date>
    </item>
  </channel>
</rss>

