<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to apply NAT to a Network Group in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/237804#M39760</link>
    <description>&lt;P&gt;In our scenario we cannot use the hide nat. There is a reason for it. I have&amp;nbsp; a different scenario. We have different third-party networks connected to our datacentre through checkpoint firewall. each third-party zone will have different network. While accessing the different third-party destination IP or vice-versa we use different NAT based on the zone. If I am adding object group in the original source, adding a /32 IP object in the original destination and and adding a /32 object in the translated source it is giving the same error like above user mentioned. This was working prior to GAIA R81. I have even rules now in my firewall in the similar way that i have stated above. But now in GAIA R81.10 it is not allowing the same similar way of adding the NAT. Can you please help me by providing some inputs&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jan 2025 11:21:46 GMT</pubDate>
    <dc:creator>KBLITSEC</dc:creator>
    <dc:date>2025-01-07T11:21:46Z</dc:date>
    <item>
      <title>How to apply NAT to a Network Group</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223560#M37239</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are planning to test a NAT configuration on R81.20.&lt;/P&gt;&lt;P&gt;If I set a Network Group as the source, the following error is displayed.&lt;/P&gt;&lt;P&gt;"The Network group is only valid if the value of the matching translated colum is 'Original' or if the translated source is 'HOST' /Address Range and the Method is Hide."&lt;/P&gt;&lt;P&gt;I want to configure NAT for a Network Group. In this case, do I need to set up Hide NAT for each individual object separately?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for all the advice.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 04:47:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223560#M37239</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2024-08-14T04:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to apply NAT to a Network Group</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223562#M37240</link>
      <description>&lt;P&gt;The network group is the Original Source? What did you set the Translated Source to?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 05:21:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223562#M37240</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-08-14T05:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to apply NAT to a Network Group</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223563#M37241</link>
      <description>&lt;P&gt;Dear emmap&lt;/P&gt;&lt;P&gt;Thank you for the reply.&lt;/P&gt;&lt;P&gt;Yes,&amp;nbsp; I want to set the Network Group as the Original Source and translate it to the IP address of the Out-side interface as the post-NAT IP address.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 05:34:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223563#M37241</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2024-08-14T05:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to apply NAT to a Network Group</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223567#M37242</link>
      <description>&lt;P&gt;I believe that should work as long as you set the translated side to Hide NAT.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 06:31:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223567#M37242</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-08-14T06:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to apply NAT to a Network Group</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223568#M37243</link>
      <description>&lt;P&gt;I mistakenly thought that I needed to add Hide NAT to the Network Group in the Original Source.&lt;/P&gt;&lt;P&gt;It turns out that I need to configure NAT for the object in the Translated Source instead.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 06:43:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223568#M37243</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2024-08-14T06:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to apply NAT to a Network Group</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223588#M37244</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/63380"&gt;@TSOL&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The easiest way to set up a NAT on a specific network, if you set it on the object itself:&lt;/P&gt;
&lt;P&gt;Here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-08-14 09_49_54-Network.png" style="width: 504px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27237iE8C1CDC9C7BDF923/image-size/large?v=v2&amp;amp;px=999" role="button" title="2024-08-14 09_49_54-Network.png" alt="2024-08-14 09_49_54-Network.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I hope it helps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Á&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 07:53:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223588#M37244</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-14T07:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to apply NAT to a Network Group</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223597#M37245</link>
      <description>&lt;P&gt;Thank you for the reply.&lt;/P&gt;&lt;P&gt;Does the response differ from the behavior when configuring NAT for the Translated Source?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 08:38:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223597#M37245</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2024-08-14T08:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to apply NAT to a Network Group</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223601#M37246</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/63380"&gt;@TSOL&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the NAT point of view, this will act as a manual hide NAT.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you configure on the network object, you will see it in the NAT table, but you can edit the rule by editing the host object.&lt;/P&gt;
&lt;P&gt;Akos&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 08:45:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223601#M37246</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-14T08:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to apply NAT to a Network Group</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223605#M37248</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/63380"&gt;@TSOL&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I told about NAT that is an easy way. If you want to do manual NAT instead, feel free, and do it, the two solution is fully equivalent.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 09:06:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223605#M37248</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-14T09:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to apply NAT to a Network Group</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223884#M37309</link>
      <description>&lt;DIV class="ai-chatbot-conversation-assistant-text css-1lxqfct"&gt;
&lt;P&gt;The below answer came from our &lt;A href="https://support.checkpoint.com/ai" target="_self"&gt;AI Copilot&lt;/A&gt;.&lt;BR /&gt;This is applicable if you want to use a manual NAT rule (versus using automatic NAT rules in the object):&lt;/P&gt;
&lt;P&gt;The error you're encountering is expected when using static NAT, which translates only one address. To configure NAT for a Network Group, you should use the Hide NAT method. Here's how you can do it:&lt;/P&gt;
&lt;H3&gt;Steps to Configure Hide NAT for a Network Group&lt;/H3&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Open SmartConsole&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and navigate to the NAT policy.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Right-click&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on the translated source object in the NAT policy.&lt;/LI&gt;
&lt;LI&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;NAT Method &amp;gt; Hide&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Install the policy&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3&gt;Important Considerations&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Hide NAT&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;allows multiple internal IP addresses to be translated to a single external IP address.&lt;/LI&gt;
&lt;LI&gt;Be cautious when using Hide NAT for a large number of hosts, as it can lead to NAT Port Exhaustion. This happens when the number of connections exceeds the available NAT ports (50,000 ports per NAT pool).&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Example Configuration&lt;/H3&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Create a Network Group&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;that includes all the networks or hosts you want to translate.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Set the Network Group&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;as the original source in the NAT rule.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Set the translated source&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to a single IP address or an address range.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Ensure the NAT method&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is set to Hide.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3&gt;Example NAT Rule&lt;/H3&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH&gt;No&lt;/TH&gt;
&lt;TH&gt;Original Source&lt;/TH&gt;
&lt;TH&gt;Original Destination&lt;/TH&gt;
&lt;TH&gt;Original Service&lt;/TH&gt;
&lt;TH&gt;Translated Source&lt;/TH&gt;
&lt;TH&gt;Translated Destination&lt;/TH&gt;
&lt;TH&gt;Translated Service&lt;/TH&gt;
&lt;TH&gt;Install On&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;1&lt;/TD&gt;
&lt;TD&gt;Network Group&lt;/TD&gt;
&lt;TD&gt;Any&lt;/TD&gt;
&lt;TD&gt;Any&lt;/TD&gt;
&lt;TD&gt;Single IP/Range&lt;/TD&gt;
&lt;TD&gt;Original&lt;/TD&gt;
&lt;TD&gt;Original&lt;/TD&gt;
&lt;TD&gt;All&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;By following these steps, you can configure Hide NAT for a Network Group without setting up Hide NAT for each individual object separately. If you encounter any issues or need further assistance, feel free to ask!&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="ai-chatbot-references css-g9n3fs"&gt;
&lt;DIV class="css-131f8vm"&gt;Learn more:&lt;/DIV&gt;
&lt;DIV class="css-zs1iv6"&gt;
&lt;OL class="css-3yupri"&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk176846" target="_blank" rel="noopener"&gt;sk176846 - "You cannot use the Network Group &amp;amp;lt;Group Name&amp;amp;gt; as the Original source" validation error when adding a network group to a NAT rule&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk179977" target="_blank" rel="noopener"&gt;sk179977 - CME error - The network group cannot be deleted because it is referenced by other objects.&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="ai-chatbot-reference css-1onth16"&gt;&lt;A class="css-a3bjub" href="http://support.checkpoint.com/results/sk/sk179917" target="_blank" rel="noopener"&gt;sk179917 - "Failed to delete object - (2) Topology: specific network must be defined" error when deleting a Network Group Object&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 16 Aug 2024 18:58:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/223884#M37309</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-16T18:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to apply NAT to a Network Group</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/237804#M39760</link>
      <description>&lt;P&gt;In our scenario we cannot use the hide nat. There is a reason for it. I have&amp;nbsp; a different scenario. We have different third-party networks connected to our datacentre through checkpoint firewall. each third-party zone will have different network. While accessing the different third-party destination IP or vice-versa we use different NAT based on the zone. If I am adding object group in the original source, adding a /32 IP object in the original destination and and adding a /32 object in the translated source it is giving the same error like above user mentioned. This was working prior to GAIA R81. I have even rules now in my firewall in the similar way that i have stated above. But now in GAIA R81.10 it is not allowing the same similar way of adding the NAT. Can you please help me by providing some inputs&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 11:21:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/237804#M39760</guid>
      <dc:creator>KBLITSEC</dc:creator>
      <dc:date>2025-01-07T11:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to apply NAT to a Network Group</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/237906#M39767</link>
      <description>&lt;P&gt;As far as I know, this behavior hasn't changed.&lt;BR /&gt;Please provide a precise example, possibly with screenshots (sensitive details can be redacted).&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 19:30:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-apply-NAT-to-a-Network-Group/m-p/237906#M39767</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-07T19:30:54Z</dc:date>
    </item>
  </channel>
</rss>

