<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inbound Hide NAT in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Inbound-Hide-NAT/m-p/34741#M7302</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Awesome!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 18 Nov 2018 03:20:20 GMT</pubDate>
    <dc:creator>Haichao_Xie</dc:creator>
    <dc:date>2018-11-18T03:20:20Z</dc:date>
    <item>
      <title>Inbound Hide NAT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Inbound-Hide-NAT/m-p/34738#M7299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to configure a policy to allow inbound access from the Internet to an internal server. I can create a NAT for the server so that the server is known by a public IP Address, but I have a problem with the return traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to translate the public Source IP address of the connection to a internal IP address. So a "Hide NAT" for inbound connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this possible? As I am failing to find any instructions for configuring this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are running R80.10 on management and security gateways.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2018 15:35:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Inbound-Hide-NAT/m-p/34738#M7299</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2018-03-09T15:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound Hide NAT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Inbound-Hide-NAT/m-p/34739#M7300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Of course it is.&lt;/P&gt;&lt;P&gt;The main issue is that the "Source" for the rule can't be "Any".&lt;/P&gt;&lt;P&gt;You also can't use negation in the NAT rulebase either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To achieve the desired result, you'll need two rules:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63813_pastedImage_1.png" style="width: 620px; height: 48px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first rule ensures the internal networks are NOT translated when they connect to the IP address (in this case, AR70).&lt;/P&gt;&lt;P&gt;"Protected Networks" is a group I created with my internal networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second rule says "anyone connecting to AR70 with appear as if it's coming from foo and going to e7".&lt;/P&gt;&lt;P&gt;"All_Internet" should be a preexisting object.&lt;/P&gt;&lt;P&gt;After you add the object to the Translated Source, you will need to need to right-click on it and change the NAT Method to Hide.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2018 20:51:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Inbound-Hide-NAT/m-p/34739#M7300</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-09T20:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound Hide NAT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Inbound-Hide-NAT/m-p/34740#M7301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for this confirmation.&amp;nbsp; With the All_Internet object (which just seems to be another way of saying any) I got it working, My main block point was not knowing that I had to right click on the "Translated source" in the NAT policy to change it from a Static NAT to a Hide NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2018 09:07:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Inbound-Hide-NAT/m-p/34740#M7301</guid>
      <dc:creator>Michael_Horne</dc:creator>
      <dc:date>2018-03-12T09:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Inbound Hide NAT</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Inbound-Hide-NAT/m-p/34741#M7302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Awesome!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Nov 2018 03:20:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Inbound-Hide-NAT/m-p/34741#M7302</guid>
      <dc:creator>Haichao_Xie</dc:creator>
      <dc:date>2018-11-18T03:20:20Z</dc:date>
    </item>
  </channel>
</rss>

