<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS incoming inspection with static NAT in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-incoming-inspection-with-static-NAT/m-p/32840#M6863</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you make the policy changes mentioned in the SK?&lt;/P&gt;&lt;P&gt;If you do that he hotfix should not be required.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Oct 2018 18:03:13 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-10-04T18:03:13Z</dc:date>
    <item>
      <title>HTTPS incoming inspection with static NAT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-incoming-inspection-with-static-NAT/m-p/32839#M6862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Hello experts,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Do you know if there are some limitation in terms of using &lt;SPAN style="background: yellow;"&gt;#HTTPS incoming inspection with static NAT#&lt;/SPAN&gt;?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Does some special configuration required when configuring &amp;nbsp;HTTPS incoming inspection with static NAT?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;In my LAB as you can see in the logs below:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;- incoming inspection without NAT to 10.1.11.3 is inspected, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;- incoming inspection with NAT to 10.1.2.10 is NOT inspected. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;I tried it with static and automatic NAT and became the same result. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;By the way: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;There is an SK on that about automatic NAT problem stating that a HF might be required. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110237"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110237&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Is a hot fix required? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71203_Capture.JPG" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2018 15:47:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-incoming-inspection-with-static-NAT/m-p/32839#M6862</guid>
      <dc:creator>Yevgeniy_Yeryom</dc:creator>
      <dc:date>2018-10-04T15:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS incoming inspection with static NAT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-incoming-inspection-with-static-NAT/m-p/32840#M6863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you make the policy changes mentioned in the SK?&lt;/P&gt;&lt;P&gt;If you do that he hotfix should not be required.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2018 18:03:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-incoming-inspection-with-static-NAT/m-p/32840#M6863</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-04T18:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS incoming inspection with static NAT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-incoming-inspection-with-static-NAT/m-p/32841#M6864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;yes I did.&amp;nbsp;&lt;BR /&gt;As shown in the screenshot, the source IP and destination IP (NAT IP representing the server) are in the same subnet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I changed the destination IP to an IP from a different subnet and the HTTPS inspection started to work. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To put together, the incoming HTTPS inspection seems to NOT work for the source and destination from the same subnet. I think this is fine for usual use cases.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2018 07:38:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-incoming-inspection-with-static-NAT/m-p/32841#M6864</guid>
      <dc:creator>Yevgeniy_Yeryom</dc:creator>
      <dc:date>2018-10-05T07:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS incoming inspection with static NAT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-incoming-inspection-with-static-NAT/m-p/32842#M6865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not familiar with a limitation relating to HTTPS Inspection being not possible in the same subnet.&lt;/P&gt;&lt;P&gt;Clearly, it's possible.&lt;/P&gt;&lt;P&gt;It may be worth a TAC case, particularly if it's a customer situation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2018 14:58:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-incoming-inspection-with-static-NAT/m-p/32842#M6865</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-05T14:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS incoming inspection with static NAT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/HTTPS-incoming-inspection-with-static-NAT/m-p/32843#M6866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually it was a test for customer, but customer will use NOT have the clients and firewall in the same subnet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, this behavior is ok for the project.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2018 13:55:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/HTTPS-incoming-inspection-with-static-NAT/m-p/32843#M6866</guid>
      <dc:creator>Yevgeniy_Yeryom</dc:creator>
      <dc:date>2018-10-08T13:55:39Z</dc:date>
    </item>
  </channel>
</rss>

