<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Router NAT translations in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269380#M45224</link>
    <description>&lt;P&gt;1) You just create manual nat rule in nat policy -&amp;gt; exactly how you described it&lt;/P&gt;
&lt;P&gt;2) yes, you add natted IPs as well, because technically, it would be part of vpn domain. I dont see an issue with mismatch, since those would be part of the vpn tunnel as well.&lt;/P&gt;</description>
    <pubDate>Sun, 01 Feb 2026 18:13:30 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2026-02-01T18:13:30Z</dc:date>
    <item>
      <title>Cisco Router NAT translations</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269374#M45220</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;We are in the process of replacing the Cisco router (R2) with a Check Point firewall and have attached the topology.&lt;/P&gt;&lt;P&gt;Since Smart move supports only ASA/FTD, I'd like to understand the VPN domain/NAT and need some help please&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Below are the NAT translations on R2.&lt;/P&gt;&lt;P&gt;R2# ip nat inside source static 10.219.24.3 192.168.85.25&lt;/P&gt;&lt;P&gt;R2# ip nat outside source static 192.168.88.4 10.14.11.6&lt;/P&gt;&lt;P&gt;!!&lt;/P&gt;&lt;P&gt;R2# ip route 10.14.11.6 255.255.255.255 192.168.1.1&lt;/P&gt;&lt;P&gt;!!&lt;/P&gt;&lt;P&gt;ip access-list extended VPN_ACL&lt;BR /&gt;permit ip host 192.168.85.25 host 192.168.88.4&lt;/P&gt;&lt;P&gt;1. How should I configure the equivalent NAT in checkpoint?&lt;/P&gt;&lt;P&gt;Static NAT:&lt;/P&gt;&lt;P&gt;Each rule for Source&lt;/P&gt;&lt;P&gt;Original Source: 10.219.24.3&lt;BR /&gt;Original Destination: Any&lt;BR /&gt;Original Services: Any&lt;BR /&gt;Translated Source: 192.168.85.25&lt;BR /&gt;Translated Destination: original&lt;BR /&gt;Translated Services: original&lt;/P&gt;&lt;P&gt;!!&lt;/P&gt;&lt;P&gt;Each rule for Destination&lt;/P&gt;&lt;P&gt;Original Source: Any&lt;BR /&gt;Original Destination:&amp;nbsp;192.168.88.4&lt;BR /&gt;Original Services: Any&lt;BR /&gt;Translated Source:&amp;nbsp;original&lt;BR /&gt;Translated Destination:&amp;nbsp;10.14.11.6&lt;BR /&gt;Translated Services: original&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;Manual NAT:-&lt;/P&gt;&lt;P&gt;Original Source: 10.219.24.3&lt;BR /&gt;Original Destination:&amp;nbsp;192.168.88.4&amp;nbsp;&lt;BR /&gt;Original Services: Any&lt;BR /&gt;Translated Source: 192.168.85.25&lt;BR /&gt;Translated Destination:&amp;nbsp;10.14.11.6&lt;BR /&gt;Translated Services: original&lt;/P&gt;&lt;P&gt;2. I believe the below one should be the encryption domain in CP. Is that correct?&lt;/P&gt;&lt;P&gt;Local Encryption Domain: 192.168.85.25/32&lt;BR /&gt;Remote Encryption Domain: 192.168.88.4/32&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Feb 2026 17:37:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269374#M45220</guid>
      <dc:creator>SriNarasimha005</dc:creator>
      <dc:date>2026-02-01T17:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router NAT translations</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269377#M45221</link>
      <description>&lt;P&gt;Thats what it would appear to be, yes. if natting is involved, those IPs would also need to be in vpn domain as well.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Feb 2026 18:02:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269377#M45221</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-01T18:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router NAT translations</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269379#M45223</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;1. Can you please confirm on the NAT statements on how it should be? Is it a Static NAT for each and every statement or can it be combined into a Manual NAT?&lt;/P&gt;&lt;P&gt;2. I believe the Pre-NAT IP should be in the VPN domain. If I add NAT IP's also in the VPN domain, will it cause phase-2 to drop due to mismatch in the "Interesting ACL" between Cisco Router and CP?&lt;/P&gt;</description>
      <pubDate>Sun, 01 Feb 2026 18:10:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269379#M45223</guid>
      <dc:creator>SriNarasimha005</dc:creator>
      <dc:date>2026-02-01T18:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router NAT translations</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269380#M45224</link>
      <description>&lt;P&gt;1) You just create manual nat rule in nat policy -&amp;gt; exactly how you described it&lt;/P&gt;
&lt;P&gt;2) yes, you add natted IPs as well, because technically, it would be part of vpn domain. I dont see an issue with mismatch, since those would be part of the vpn tunnel as well.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Feb 2026 18:13:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269380#M45224</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-01T18:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router NAT translations</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269392#M45225</link>
      <description>&lt;P&gt;I assume this is domain based tunnel?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 03:13:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269392#M45225</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-02T03:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router NAT translations</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269403#M45228</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, this is a domain-based tunnel as the peer device- Cisco router uses ACL under crypto map.&lt;/P&gt;&lt;P&gt;I'd like to get this clarified on the NAT again&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The below statements are configured on the R2 router. Since these are Interface based in Cisco routers, can you please let me know if the Manual NAT to be configured uni-directionally or it needs to be combined into a single NAT statement?&lt;/P&gt;&lt;P&gt;R2# ip nat inside source static 10.219.24.3 192.168.85.25&lt;/P&gt;&lt;P&gt;R2# ip nat outside source static 192.168.88.4 10.14.11.6&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 11:57:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269403#M45228</guid>
      <dc:creator>SriNarasimha005</dc:creator>
      <dc:date>2026-02-02T11:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router NAT translations</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269404#M45229</link>
      <description>&lt;P&gt;Just create 2 separate nat rules.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 12:04:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269404#M45229</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-02T12:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router NAT translations</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269405#M45230</link>
      <description>&lt;P&gt;&lt;SPAN&gt;On the Check Point side you need two NAT rules (one Source NAT, one Destination NAT) plus the corresponding Access Control (firewall) rules to allow the traffic.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 12:06:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269405#M45230</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-02-02T12:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router NAT translations</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269451#M45249</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/16383"&gt;@Vincent_Bacher&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply. Final one.&lt;/P&gt;&lt;P&gt;For the NAT'd IP, there is a route configured on the Cisco router towards the next-hop i.e R1. It automatically generates a host route for the translated address in the routing table, ensuring correct return routing from the inside network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since CP doesn't route back based on the source NAT IP, I believe this can be ignored. Is my understanding correct?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;R2# ip route 10.14.11.6 255.255.255.255 &amp;lt;R1 Next-Hop&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 16:22:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269451#M45249</guid>
      <dc:creator>SriNarasimha005</dc:creator>
      <dc:date>2026-02-02T16:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router NAT translations</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269456#M45251</link>
      <description>&lt;P&gt;Thats right.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 16:44:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269456#M45251</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-02T16:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router NAT translations</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269460#M45254</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/12036"&gt;@SriNarasimha005&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ping me if u need remote, happy to go over things.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 17:03:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269460#M45254</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-02T17:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router NAT translations</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269461#M45255</link>
      <description>&lt;P&gt;Sure, will do. Thanks a lot mate&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":folded_hands:"&gt;🙏&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 17:06:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269461#M45255</guid>
      <dc:creator>SriNarasimha005</dc:creator>
      <dc:date>2026-02-02T17:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Router NAT translations</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269462#M45256</link>
      <description>&lt;P&gt;Im always happy to try and help, no issue. I wish I were a Superman to fix anything and everything, but not possible lol&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 17:22:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Cisco-Router-NAT-translations/m-p/269462#M45256</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-02T17:22:53Z</dc:date>
    </item>
  </channel>
</rss>

