<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to create destination NAT rule for ICMP service in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-create-destination-NAT-rule-for-ICMP-service/m-p/238631#M39842</link>
    <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Configuring-NAT-Policy.htm?TocPath=Creating%20an%20Access%20Control%20Policy%7CConfiguring%20the%20NAT%20Policy%7C_____0" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Configuring-NAT-Policy.htm?TocPath=Creating%20an%20Access%20Control%20Policy%7CConfiguring%20the%20NAT%20Policy%7C_____0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;NAT (Network Address Translation) is a feature of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_fwcap variable"&gt;Firewall&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_sblade variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_SecurityManagement_AdminGuide/Topics-SECMG/Configuring-NAT-Policy.htm?TocPath=Creating%20an%20Access%20Control%20Policy%7CConfiguring%20the%20NAT%20Policy%7C_____0#" data-mc-state="closed" data-aria-describedby="ea9a5e90-ba03-412b-8fb5-0bbd4b610425" target="_blank"&gt;Software Blade&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Lesley_0-1736930943173.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29221i2BB3AA58046F195F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Lesley_0-1736930943173.gif" alt="Lesley_0-1736930943173.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and replaces IPv4 and IPv6 addresses to add more security. NAT protects the identity of a network and does not show internal IP addresses to the Internet.&lt;/P&gt;
&lt;P&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;can change:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;The source IP address in a packet.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The destination IP address in a packet.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The TCP / UDP port in a packet. (ICMP is not TCP or UDP)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Wed, 15 Jan 2025 08:49:20 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2025-01-15T08:49:20Z</dc:date>
    <item>
      <title>Unable to create destination NAT rule for ICMP service</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-create-destination-NAT-rule-for-ICMP-service/m-p/238605#M39835</link>
      <description>&lt;P&gt;Dear Checkmates,&lt;/P&gt;&lt;P&gt;I'm having problem creating DST NAT rule for an ICMP traffic, I'm forced to create a rule with services as "ANY" for this to work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone let me know if this is a limitation and so please share the relevant document from Check Point.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;=======&lt;/P&gt;&lt;P&gt;WR,&lt;/P&gt;&lt;P&gt;FH&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 07:12:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-create-destination-NAT-rule-for-ICMP-service/m-p/238605#M39835</guid>
      <dc:creator>Firewall_Head</dc:creator>
      <dc:date>2025-01-15T07:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to create destination NAT rule for ICMP service</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-create-destination-NAT-rule-for-ICMP-service/m-p/238631#M39842</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Configuring-NAT-Policy.htm?TocPath=Creating%20an%20Access%20Control%20Policy%7CConfiguring%20the%20NAT%20Policy%7C_____0" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Configuring-NAT-Policy.htm?TocPath=Creating%20an%20Access%20Control%20Policy%7CConfiguring%20the%20NAT%20Policy%7C_____0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;NAT (Network Address Translation) is a feature of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_fwcap variable"&gt;Firewall&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_sblade variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_SecurityManagement_AdminGuide/Topics-SECMG/Configuring-NAT-Policy.htm?TocPath=Creating%20an%20Access%20Control%20Policy%7CConfiguring%20the%20NAT%20Policy%7C_____0#" data-mc-state="closed" data-aria-describedby="ea9a5e90-ba03-412b-8fb5-0bbd4b610425" target="_blank"&gt;Software Blade&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Lesley_0-1736930943173.gif" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29221i2BB3AA58046F195F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Lesley_0-1736930943173.gif" alt="Lesley_0-1736930943173.gif" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and replaces IPv4 and IPv6 addresses to add more security. NAT protects the identity of a network and does not show internal IP addresses to the Internet.&lt;/P&gt;
&lt;P&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;can change:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;The source IP address in a packet.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The destination IP address in a packet.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;The TCP / UDP port in a packet. (ICMP is not TCP or UDP)&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 15 Jan 2025 08:49:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-create-destination-NAT-rule-for-ICMP-service/m-p/238631#M39842</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-01-15T08:49:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to create destination NAT rule for ICMP service</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-create-destination-NAT-rule-for-ICMP-service/m-p/238651#M39850</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Destination-NAT-with-ICMP/m-p/19275#M16164" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Destination-NAT-with-ICMP/m-p/19275#M16164&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk66506" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk66506: &lt;STRONG&gt;ICMP&lt;/STRONG&gt; Error packets are not translated according to &lt;STRONG&gt;NAT&lt;/STRONG&gt; rulebase&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk172933" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk172933: &lt;STRONG&gt;NAT&lt;/STRONG&gt; FAQ&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 11:18:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-create-destination-NAT-rule-for-ICMP-service/m-p/238651#M39850</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-01-15T11:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to create destination NAT rule for ICMP service</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-create-destination-NAT-rule-for-ICMP-service/m-p/238703#M39859</link>
      <description>&lt;P&gt;The NAT rulebase only permits usage of TCP and UDP services.&amp;nbsp;&lt;BR /&gt;I don't believe this is explicitly documented as SmartConsole provides an appropriate error when you attempt this configuration.&lt;BR /&gt;This is also a long-standing limitation going back to the earliest days of the product.&lt;/P&gt;
&lt;P&gt;Having said that, the NAT rulebase only applies if the traffic is permitted by the Access Policy.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 19:49:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-create-destination-NAT-rule-for-ICMP-service/m-p/238703#M39859</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-15T19:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to create destination NAT rule for ICMP service</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Unable-to-create-destination-NAT-rule-for-ICMP-service/m-p/238706#M39861</link>
      <description>&lt;P&gt;You get a validation error when you try to sneak ICMP in a group in the rule. If you try to select icmp itself you cannot find it to select in the drop down menu&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 19:58:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Unable-to-create-destination-NAT-rule-for-ICMP-service/m-p/238706#M39861</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-01-15T19:58:02Z</dc:date>
    </item>
  </channel>
</rss>

