<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Smartconsole with NAT to the manager doesnt work in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Smartconsole-with-NAT-to-the-manager-doesnt-work/m-p/282108#M46945</link>
    <description>&lt;P&gt;I haven't tried it, I did look at it but I believe that scenario is for gateways connecting to their manager via NAT, this is purely the operator connecting via smart console behind NAT. ideally the manager never would see this faked IP, its un-nated before it gets there, but it seems to send it as part of a potential MDS domain lookup.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Sep 2026 00:54:13 GMT</pubDate>
    <dc:creator>Ryan_Ryan</dc:creator>
    <dc:date>2026-09-10T00:54:13Z</dc:date>
    <item>
      <title>Smartconsole with NAT to the manager doesnt work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Smartconsole-with-NAT-to-the-manager-doesnt-work/m-p/282106#M46943</link>
      <description>&lt;P&gt;Using R82 we have an issue connecting to our smart console via an OOB connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Whilst within the customer network connecting to smart console using the management server's real IP address works fine, however in case of a terminal server failure or the like we have a backup link into each customer and we nat every IP address.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we connect with Smart console to the NAT IP, the login works (bad password throws a bad password etc) we also get a warning if existing session is open etc, but then it will promptly stop with "Internal Error"&amp;nbsp; (Web access and SSH with NAT work fine)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CPD says:&lt;/P&gt;
&lt;P&gt;ERROR management.object_store.ObjectStoreSessionImpl [qtp-465201630-50029]: Failed to find domainIp 10.10.10.5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where 10.10.10.5 is the NAT IP we enter in Smartconsole, at a network level the manager knows nothing of this address and shouldn't see it. Our same setup used to work in R81.10, but is broken is R82 and R81.20&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2026 00:17:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Smartconsole-with-NAT-to-the-manager-doesnt-work/m-p/282106#M46943</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2026-09-10T00:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: Smartconsole with NAT to the manager doesnt work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Smartconsole-with-NAT-to-the-manager-doesnt-work/m-p/282107#M46944</link>
      <description>&lt;P&gt;Have you followed this or some other approach?&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Security_Management_behind_NAT.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Security_Management_behind_NAT.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2026 00:39:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Smartconsole-with-NAT-to-the-manager-doesnt-work/m-p/282107#M46944</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-09-10T00:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: Smartconsole with NAT to the manager doesnt work</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Smartconsole-with-NAT-to-the-manager-doesnt-work/m-p/282108#M46945</link>
      <description>&lt;P&gt;I haven't tried it, I did look at it but I believe that scenario is for gateways connecting to their manager via NAT, this is purely the operator connecting via smart console behind NAT. ideally the manager never would see this faked IP, its un-nated before it gets there, but it seems to send it as part of a potential MDS domain lookup.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2026 00:54:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Smartconsole-with-NAT-to-the-manager-doesnt-work/m-p/282108#M46945</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2026-09-10T00:54:13Z</dc:date>
    </item>
  </channel>
</rss>

