<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ConnectControl / Logical Servers within same subnet in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/ConnectControl-Logical-Servers-within-same-subnet/m-p/30766#M6409</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;"Any" in original was the first attempt I made (CISS)&lt;/P&gt;&lt;P&gt;But install aborts: "Invalid &amp;lt;Any&amp;gt; in Source of Address Translation Rule ##. &amp;lt;Any&amp;gt; is valid&amp;nbsp;only it the matching Translated column is &amp;lt;Original&amp;gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But many thanks to you, your reply&amp;nbsp;pushed me back to test with NAT and I found a solution:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the summary what the tasks are to make an logical-server reachable from the same subnet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Create 2 access-rule for VIP and the corresponding Server-Group (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk87641"&gt;sk87641&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;Create manual-proxy-arp for VIP (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30197"&gt;sk30197&lt;/A&gt;)&lt;UL&gt;&lt;LI&gt;In HA-Mode with VMAC use Real-IP of cluster member and VMAC&lt;/LI&gt;&lt;LI&gt;do not use interface otherwise&amp;nbsp;physical MAC of interface will be used)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Create NAT rule: "same-subnet" -&amp;gt; "&lt;SPAN&gt;corresponding server-group" =&amp;gt; "Cluster-object"&amp;nbsp;(Hide) -&amp;gt; "original" (No sk found)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you very much for spending your time with my problems.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sascha&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Feb 2019 09:51:04 GMT</pubDate>
    <dc:creator>Sascha_Bremshey</dc:creator>
    <dc:date>2019-02-13T09:51:04Z</dc:date>
    <item>
      <title>ConnectControl / Logical Servers within same subnet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ConnectControl-Logical-Servers-within-same-subnet/m-p/30762#M6405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;currenty I'm experimenting with Logical Servers.&lt;/P&gt;&lt;P&gt;So far it works fine but there is one point on my list I'm unable to resolve.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to access my logical server from inside the same subnet as the VIP and the real servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I managed to set up proxy arp so reqests are forwardet from GW to destination server(s).&lt;BR /&gt;Packets are recevived from server(s) but as the src. address is located in the same subnet the replays are send to src directly.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Aswer packets arrive at the client but with real server IP and not VIP -&amp;gt; packets did not pass trough GW so no reverse NAT happend.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;To resolve this I think I only have to src-NAT all my connections if they are from same subnet to an IP which is behind Gateway (from servers view)&lt;/P&gt;&lt;P&gt;BUT as ConnectControl is only a more inteligent destination NAT method working as impied rule (0) my src.Nat rules will never match.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for reading &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/BR&lt;/P&gt;&lt;P&gt;Sascha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2019 14:46:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ConnectControl-Logical-Servers-within-same-subnet/m-p/30762#M6405</guid>
      <dc:creator>Sascha_Bremshey</dc:creator>
      <dc:date>2019-02-05T14:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: ConnectControl / Logical Servers within same subnet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ConnectControl-Logical-Servers-within-same-subnet/m-p/30763#M6406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What specific NAT rules have you tried?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2019 23:37:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ConnectControl-Logical-Servers-within-same-subnet/m-p/30763#M6406</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-08T23:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: ConnectControl / Logical Servers within same subnet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ConnectControl-Logical-Servers-within-same-subnet/m-p/30764#M6407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've tried:&lt;/P&gt;&lt;P&gt;ORG-SRC;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;ORG-DST; &amp;nbsp;&amp;nbsp;&amp;nbsp;ORG-SRV; &amp;nbsp;&amp;nbsp;&amp;nbsp;TRA-SRC; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;TRA-DST;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;TRA-SRV&lt;/P&gt;&lt;P&gt;Subnet-of-VIP;&amp;nbsp;&amp;nbsp;&amp;nbsp;VIP;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;ANY; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Subnet-of-VIP-GW-IP(Hide); &amp;nbsp;&amp;nbsp; &lt;SPAN&gt;Original&lt;/SPAN&gt;;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Original&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In log I can see that NAT rule 0 matched (Which is the Logical-Server magic) but my NAT rule did not match.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Feb 2019 07:21:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ConnectControl-Logical-Servers-within-same-subnet/m-p/30764#M6407</guid>
      <dc:creator>Sascha_Bremshey</dc:creator>
      <dc:date>2019-02-11T07:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: ConnectControl / Logical Servers within same subnet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ConnectControl-Logical-Servers-within-same-subnet/m-p/30765#M6408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I &lt;EM&gt;&lt;STRONG&gt;think&lt;/STRONG&gt;&lt;/EM&gt; you might have to make Original Source "any" in this context.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Feb 2019 16:49:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ConnectControl-Logical-Servers-within-same-subnet/m-p/30765#M6408</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-11T16:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: ConnectControl / Logical Servers within same subnet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ConnectControl-Logical-Servers-within-same-subnet/m-p/30766#M6409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;"Any" in original was the first attempt I made (CISS)&lt;/P&gt;&lt;P&gt;But install aborts: "Invalid &amp;lt;Any&amp;gt; in Source of Address Translation Rule ##. &amp;lt;Any&amp;gt; is valid&amp;nbsp;only it the matching Translated column is &amp;lt;Original&amp;gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But many thanks to you, your reply&amp;nbsp;pushed me back to test with NAT and I found a solution:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the summary what the tasks are to make an logical-server reachable from the same subnet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Create 2 access-rule for VIP and the corresponding Server-Group (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk87641"&gt;sk87641&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;Create manual-proxy-arp for VIP (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30197"&gt;sk30197&lt;/A&gt;)&lt;UL&gt;&lt;LI&gt;In HA-Mode with VMAC use Real-IP of cluster member and VMAC&lt;/LI&gt;&lt;LI&gt;do not use interface otherwise&amp;nbsp;physical MAC of interface will be used)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Create NAT rule: "same-subnet" -&amp;gt; "&lt;SPAN&gt;corresponding server-group" =&amp;gt; "Cluster-object"&amp;nbsp;(Hide) -&amp;gt; "original" (No sk found)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you very much for spending your time with my problems.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sascha&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2019 09:51:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ConnectControl-Logical-Servers-within-same-subnet/m-p/30766#M6409</guid>
      <dc:creator>Sascha_Bremshey</dc:creator>
      <dc:date>2019-02-13T09:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: ConnectControl / Logical Servers within same subnet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ConnectControl-Logical-Servers-within-same-subnet/m-p/30767#M6410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm glad you figured it out &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;I was actually trying to find how we did this with AWS and ELBs, which also used these objects.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe you need to do something similar with NAT rules there.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2019 19:13:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ConnectControl-Logical-Servers-within-same-subnet/m-p/30767#M6410</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-13T19:13:07Z</dc:date>
    </item>
  </channel>
</rss>

