<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic static NAT in VPN tunel in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/static-NAT-in-VPN-tunel/m-p/265820#M44732</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;I have a working VPN S2S tunnel between CheckPoint and SonicWall FW.&lt;BR /&gt;On CheckPoint site we need to NAT a 10.x.x.x address (static NAT) so from the SonicWall site a VPN connection can be opened to our internal host.&lt;BR /&gt;When I adjust the host object adding a static NAT to it, I can see in the logs, that the host IP is not natted and dropped by the firewall.&lt;/P&gt;&lt;P&gt;do you have any hint, how the NAT within out VPN tunnel can be achieved ?&lt;/P&gt;&lt;P&gt;OurHost(10.10.10.10, static NAT 122.122.122.10)&lt;/P&gt;&lt;P&gt;working VPN (with no NAT rules):&lt;/P&gt;&lt;P&gt;PartnerHost 100.100.100.1&amp;nbsp; -&amp;gt; OurHost(ORIG IP 10.10.10.10)&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Needed connection (using NAT):&lt;/P&gt;&lt;P&gt;PartnerHost 100.100.100.1&amp;nbsp; -&amp;gt; OurHost(NAT 122.122.122.10)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any hint how to configure this ?&lt;BR /&gt;As we have many working VPN connections, a global setting change may impact other VPNs.&lt;/P&gt;&lt;P&gt;The SonicWall may not even open a VPN in case there is a little issue with the NAT.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Dec 2025 14:53:09 GMT</pubDate>
    <dc:creator>Tecki0815</dc:creator>
    <dc:date>2025-12-19T14:53:09Z</dc:date>
    <item>
      <title>static NAT in VPN tunel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/static-NAT-in-VPN-tunel/m-p/265820#M44732</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I have a working VPN S2S tunnel between CheckPoint and SonicWall FW.&lt;BR /&gt;On CheckPoint site we need to NAT a 10.x.x.x address (static NAT) so from the SonicWall site a VPN connection can be opened to our internal host.&lt;BR /&gt;When I adjust the host object adding a static NAT to it, I can see in the logs, that the host IP is not natted and dropped by the firewall.&lt;/P&gt;&lt;P&gt;do you have any hint, how the NAT within out VPN tunnel can be achieved ?&lt;/P&gt;&lt;P&gt;OurHost(10.10.10.10, static NAT 122.122.122.10)&lt;/P&gt;&lt;P&gt;working VPN (with no NAT rules):&lt;/P&gt;&lt;P&gt;PartnerHost 100.100.100.1&amp;nbsp; -&amp;gt; OurHost(ORIG IP 10.10.10.10)&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Needed connection (using NAT):&lt;/P&gt;&lt;P&gt;PartnerHost 100.100.100.1&amp;nbsp; -&amp;gt; OurHost(NAT 122.122.122.10)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any hint how to configure this ?&lt;BR /&gt;As we have many working VPN connections, a global setting change may impact other VPNs.&lt;/P&gt;&lt;P&gt;The SonicWall may not even open a VPN in case there is a little issue with the NAT.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 14:53:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/static-NAT-in-VPN-tunel/m-p/265820#M44732</guid>
      <dc:creator>Tecki0815</dc:creator>
      <dc:date>2025-12-19T14:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: static NAT in VPN tunel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/static-NAT-in-VPN-tunel/m-p/265825#M44733</link>
      <description>&lt;P&gt;Since you are configuring the static NAT on the host object, check this option within the VPN community, it should be unchecked for this scenario.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="disable-nat.png" style="width: 659px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32518i151835ABA4EF2CE8/image-size/large?v=v2&amp;amp;px=999" role="button" title="disable-nat.png" alt="disable-nat.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 16:49:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/static-NAT-in-VPN-tunel/m-p/265825#M44733</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-12-19T16:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: static NAT in VPN tunel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/static-NAT-in-VPN-tunel/m-p/265826#M44734</link>
      <description>&lt;P&gt;Pretty much you configure manual static nat rue and as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/75772"&gt;@CaseyB&lt;/a&gt;&amp;nbsp;said, make sure that option is disabled inside community object.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 17:06:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/static-NAT-in-VPN-tunel/m-p/265826#M44734</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-19T17:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: static NAT in VPN tunel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/static-NAT-in-VPN-tunel/m-p/265912#M44741</link>
      <description>&lt;P&gt;Additional to the mentioned setting, please also check that the 122.122.122.10 is within your VPN Domain (formerly called Encryption Domain) and that the ruleset also allows the connection to the NAT IP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Dec 2025 13:53:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/static-NAT-in-VPN-tunel/m-p/265912#M44741</guid>
      <dc:creator>ThomasH</dc:creator>
      <dc:date>2025-12-23T13:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: static NAT in VPN tunel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/static-NAT-in-VPN-tunel/m-p/266004#M44751</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Were you able to sort this out?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Dec 2025 05:13:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/static-NAT-in-VPN-tunel/m-p/266004#M44751</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-25T05:13:06Z</dc:date>
    </item>
  </channel>
</rss>

