<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain objects in NAT policy in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-NAT-policy/m-p/33634#M7072</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since manual NAT is checked first, this would always be matched... Also I would like to use range of addresses instead of one&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 07 Oct 2018 21:51:40 GMT</pubDate>
    <dc:creator>Usman_Shaikh</dc:creator>
    <dc:date>2018-10-07T21:51:40Z</dc:date>
    <item>
      <title>Domain objects in NAT policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-NAT-policy/m-p/33632#M7070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; color: black;"&gt;Hi Experts&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; color: black;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; color: black;"&gt;We current have a manual hide NAT in place for our internet traffic that translates our internal addresses to a publicly routable address on the external interface (call it eth1) of the firewall when accessing ALL Non-RFC addresses&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; color: black;"&gt;&amp;nbsp;We now have a requirement to set up NAT for Azure Microsoft peering that uses a different outgoing interface (eth2) on the same firewall that is on a different public subnet(Routing is already setup using BGP for MS prefixes to go out via eth2)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; color: black;"&gt;Since the destination is this case is dynamic Microsoft domains only, I was thinking along the lines of using Domain objects in order to avoid creating (and then manage) individual network objects that represent Microsoft IP prefixes.. However domain objects can only be used in access policy rules and not in NAT rules; therefore I am looking for best possible way to achieve this&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; color: black;"&gt;(Additionally I would like to use a pool of translated addresses and not having to use just the interface address due to limittion of 65k sessions)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; color: black;"&gt;Deployment: VSX on R80.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; color: black;"&gt;Desired rulebase&lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE class="j-table jiveBorder" height="114" style="border: 1px solid #c6c6c6; width: 763px;"&gt;&lt;THEAD&gt;&lt;TR style="background-color: #efefef;"&gt;&lt;TH style="width: 111px;"&gt;Rule&lt;/TH&gt;&lt;TH style="width: 123px;"&gt;Original Source&lt;/TH&gt;&lt;TH style="width: 155px;"&gt;Original Destination&lt;/TH&gt;&lt;TH style="width: 181px;"&gt;&lt;P&gt;Translated Source&lt;/P&gt;&lt;P&gt;(Example only)&lt;/P&gt;&lt;/TH&gt;&lt;TH style="width: 135px;"&gt;Trasnlated Destination&lt;/TH&gt;&lt;/TR&gt;&lt;/THEAD&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="width: 111px;"&gt;Internet-Access&lt;/TD&gt;&lt;TD style="width: 123px;"&gt;Internal-Networks&lt;/TD&gt;&lt;TD style="width: 155px;"&gt;Any&lt;/TD&gt;&lt;TD style="width: 181px;"&gt;&lt;P&gt;1.1.1.1&lt;/P&gt;&lt;P&gt;(IP on eth1 subnet)&lt;/P&gt;&lt;/TD&gt;&lt;TD style="width: 135px;"&gt;Original&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="width: 111px;"&gt;Azure-Access&lt;/TD&gt;&lt;TD style="width: 123px;"&gt;Internal-Networks&lt;/TD&gt;&lt;TD style="width: 155px;"&gt;&amp;lt;&lt;EM&gt;Microsoft Domains&lt;/EM&gt;&amp;gt;&lt;/TD&gt;&lt;TD style="width: 181px;"&gt;&lt;P&gt;2.2.2.1 - 2.2.2.10&lt;/P&gt;&lt;P&gt;(IP range on eth2 subnet)&lt;/P&gt;&lt;/TD&gt;&lt;TD style="width: 135px;"&gt;Original&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Oct 2018 21:08:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-NAT-policy/m-p/33632#M7070</guid>
      <dc:creator>Usman_Shaikh</dc:creator>
      <dc:date>2018-10-07T21:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: Domain objects in NAT policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-NAT-policy/m-p/33633#M7071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you need just to c&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30557"&gt;onfigure automatic NAT&lt;/A&gt; to use hide behind gateway setting instead of both manual NAT rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Oct 2018 21:32:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-NAT-policy/m-p/33633#M7071</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-10-07T21:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: Domain objects in NAT policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-NAT-policy/m-p/33634#M7072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since manual NAT is checked first, this would always be matched... Also I would like to use range of addresses instead of one&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Oct 2018 21:51:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-NAT-policy/m-p/33634#M7072</guid>
      <dc:creator>Usman_Shaikh</dc:creator>
      <dc:date>2018-10-07T21:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Domain objects in NAT policy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-NAT-policy/m-p/33635#M7073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are in position to upgrade to R80.20 then maybe you could use the new updateable objects, they have Azure as option&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131852" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk131852"&gt;Updatable Objects in R80.20&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't played with them yet and don't know if they would work in NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Else dynamic objects should do the trick, you just need to script Azure IP updates &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=skI1915" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=skI1915"&gt;Configuring Dynamic Objects&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2018 07:16:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Domain-objects-in-NAT-policy/m-p/33635#M7073</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-10-08T07:16:44Z</dc:date>
    </item>
  </channel>
</rss>

