<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT policy rules for internal interfaces? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/NAT-policy-rules-for-internal-interfaces/m-p/28618#M5838</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We don't appear to be able to get a NAT rule to apply on traffic on an internal interface of a Gaia security gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Background:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;We have been using Squid proxies for over 20 years and have a variety of systems and deployment tools that have the proxy hard coded (cache.lair.co.za:3128). Whilst it is possible to enable a proxy service on security gateways and edit the default port (8080) to match our legacy environment, application control doesn’t work due to them being written only to match on direct connections (tcp:80 and tcp:443) and HTTP and HTTPS proxy connections on tcp:8080.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;We subsequently have to leave the security gateway proxy port configured as 8080 and wanted to create a NAT rule to redirect inbound connections towards the security gateway on 3128 to 8080.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;What we did:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Created a NAT rule:&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P style="padding-left: 60px;"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70796_nat_rule.jpg" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Testing:&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P style="padding-left: 60px;"&gt;&lt;SPAN style="font-size: 12px; font-family: 'courier new', courier, monospace;"&gt;&lt;SPAN style="color: #808080;"&gt;[davidh@zajnb01-kvm2c&amp;nbsp;~]#&lt;/SPAN&gt; telnet cache.lair.co.za 8080&lt;BR /&gt;Trying 100.127.254.1...&lt;BR /&gt;&lt;SPAN style="color: #008000;"&gt;Connected&lt;/SPAN&gt; to cache.lair.co.za (100.127.254.1).&lt;BR /&gt;Escape character is '^]'.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;SPAN style="font-size: 12px; font-family: 'courier new', courier, monospace;"&gt;&lt;SPAN style="color: #808080;"&gt;[&lt;/SPAN&gt;&lt;SPAN style="color: #808080;"&gt;davidh@zajnb01-kvm2c&lt;/SPAN&gt;&lt;SPAN style="color: #808080;"&gt;&amp;nbsp;~]#&lt;/SPAN&gt; telnet cache.lair.co.za 3128&lt;BR /&gt;Trying 100.127.254.1...&lt;BR /&gt;telnet: connect to address 100.127.254.1: &lt;SPAN style="color: #ff6600;"&gt;Connection refused&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Are there restrictions on NAT policies that I'm perhaps unaware of?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Sep 2018 12:57:38 GMT</pubDate>
    <dc:creator>David_Herselman</dc:creator>
    <dc:date>2018-09-21T12:57:38Z</dc:date>
    <item>
      <title>NAT policy rules for internal interfaces?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-policy-rules-for-internal-interfaces/m-p/28618#M5838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We don't appear to be able to get a NAT rule to apply on traffic on an internal interface of a Gaia security gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Background:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;We have been using Squid proxies for over 20 years and have a variety of systems and deployment tools that have the proxy hard coded (cache.lair.co.za:3128). Whilst it is possible to enable a proxy service on security gateways and edit the default port (8080) to match our legacy environment, application control doesn’t work due to them being written only to match on direct connections (tcp:80 and tcp:443) and HTTP and HTTPS proxy connections on tcp:8080.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;We subsequently have to leave the security gateway proxy port configured as 8080 and wanted to create a NAT rule to redirect inbound connections towards the security gateway on 3128 to 8080.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;What we did:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Created a NAT rule:&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P style="padding-left: 60px;"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70796_nat_rule.jpg" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Testing:&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P style="padding-left: 60px;"&gt;&lt;SPAN style="font-size: 12px; font-family: 'courier new', courier, monospace;"&gt;&lt;SPAN style="color: #808080;"&gt;[davidh@zajnb01-kvm2c&amp;nbsp;~]#&lt;/SPAN&gt; telnet cache.lair.co.za 8080&lt;BR /&gt;Trying 100.127.254.1...&lt;BR /&gt;&lt;SPAN style="color: #008000;"&gt;Connected&lt;/SPAN&gt; to cache.lair.co.za (100.127.254.1).&lt;BR /&gt;Escape character is '^]'.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 60px;"&gt;&lt;SPAN style="font-size: 12px; font-family: 'courier new', courier, monospace;"&gt;&lt;SPAN style="color: #808080;"&gt;[&lt;/SPAN&gt;&lt;SPAN style="color: #808080;"&gt;davidh@zajnb01-kvm2c&lt;/SPAN&gt;&lt;SPAN style="color: #808080;"&gt;&amp;nbsp;~]#&lt;/SPAN&gt; telnet cache.lair.co.za 3128&lt;BR /&gt;Trying 100.127.254.1...&lt;BR /&gt;telnet: connect to address 100.127.254.1: &lt;SPAN style="color: #ff6600;"&gt;Connection refused&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Are there restrictions on NAT policies that I'm perhaps unaware of?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2018 12:57:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-policy-rules-for-internal-interfaces/m-p/28618#M5838</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-21T12:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: NAT policy rules for internal interfaces?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-policy-rules-for-internal-interfaces/m-p/28619#M5839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are not traversing the firewall. You are trying to connect to it on a different port to begin with.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2018 13:23:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-policy-rules-for-internal-interfaces/m-p/28619#M5839</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-09-21T13:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: NAT policy rules for internal interfaces?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-policy-rules-for-internal-interfaces/m-p/28620#M5840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, I'll NAT the connection before it reaches the Check Point then...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2018 15:30:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-policy-rules-for-internal-interfaces/m-p/28620#M5840</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-21T15:30:06Z</dc:date>
    </item>
  </channel>
</rss>

