<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote Access VPN with NATed IP Address in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-NATed-IP-Address/m-p/92462#M10079</link>
    <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;I have a requirement to configure Remote Access VPN on a client’s firewall. Below is the setup details:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Gaia R80.40 ClusterXL Gateways&lt;/LI&gt;&lt;LI&gt;Gaia R80.40 Security Management Server&lt;/LI&gt;&lt;LI&gt;Firewall is behind the internet router and internet link is terminated on the internet router.&lt;/LI&gt;&lt;LI&gt;Checkpoint cluster and the internet router are connected through a private network. (I.e. cluster’s external interface has private IP addresses configured on it 10.10.10.x-VIP, 10.10.10.y-FW1 Physical-IP and 10.10.10.z-FW2 Physical&amp;nbsp; IP).&lt;/LI&gt;&lt;LI&gt;There are multiple servers hosted behind this firewall cluster which are NATed on the firewall with public IP addresses. All these servers work properly.&lt;/LI&gt;&lt;LI&gt;All the users who access the internet, are NATed behind the firewall (hide NAT with public IP addresses). This access works properly as well.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Now my client needs to enable remote access VPN on this firewall.&lt;/P&gt;&lt;P&gt;My query is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Where should the Public IP be NATed on which VPN connection will be established?&lt;/LI&gt;&lt;LI&gt;Will it work if I statically NAT my external virtual IP address with the VPN public IP address, on the Firewall Cluster itself?&lt;/LI&gt;&lt;LI&gt;Or it must be NATed on the internet router only?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Sat, 25 Jul 2020 22:42:11 GMT</pubDate>
    <dc:creator>Abhas_Vijayvarg</dc:creator>
    <dc:date>2020-07-25T22:42:11Z</dc:date>
    <item>
      <title>Remote Access VPN with NATed IP Address</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-NATed-IP-Address/m-p/92462#M10079</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;I have a requirement to configure Remote Access VPN on a client’s firewall. Below is the setup details:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Gaia R80.40 ClusterXL Gateways&lt;/LI&gt;&lt;LI&gt;Gaia R80.40 Security Management Server&lt;/LI&gt;&lt;LI&gt;Firewall is behind the internet router and internet link is terminated on the internet router.&lt;/LI&gt;&lt;LI&gt;Checkpoint cluster and the internet router are connected through a private network. (I.e. cluster’s external interface has private IP addresses configured on it 10.10.10.x-VIP, 10.10.10.y-FW1 Physical-IP and 10.10.10.z-FW2 Physical&amp;nbsp; IP).&lt;/LI&gt;&lt;LI&gt;There are multiple servers hosted behind this firewall cluster which are NATed on the firewall with public IP addresses. All these servers work properly.&lt;/LI&gt;&lt;LI&gt;All the users who access the internet, are NATed behind the firewall (hide NAT with public IP addresses). This access works properly as well.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Now my client needs to enable remote access VPN on this firewall.&lt;/P&gt;&lt;P&gt;My query is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Where should the Public IP be NATed on which VPN connection will be established?&lt;/LI&gt;&lt;LI&gt;Will it work if I statically NAT my external virtual IP address with the VPN public IP address, on the Firewall Cluster itself?&lt;/LI&gt;&lt;LI&gt;Or it must be NATed on the internet router only?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jul 2020 22:42:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-NATed-IP-Address/m-p/92462#M10079</guid>
      <dc:creator>Abhas_Vijayvarg</dc:creator>
      <dc:date>2020-07-25T22:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN with NATed IP Address</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-NATed-IP-Address/m-p/92463#M10080</link>
      <description>&lt;P&gt;Whatever NAT IP on the router routes to the VIP, you&amp;nbsp;need to configure as the IP for Link Selection in the cluster object.&lt;BR /&gt;That should allow VPN (either site-to-site or remote access) to work.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jul 2020 19:02:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-NATed-IP-Address/m-p/92463#M10080</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-25T19:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN with NATed IP Address</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-NATed-IP-Address/m-p/92466#M10081</link>
      <description>&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;Thank you for a quick response.&lt;/P&gt;&lt;P&gt;Is that the only way of achieving it? If NAT is not configurable on the router, can I do the NAT on the firewall cluster itself and achieve the same goal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jul 2020 22:41:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-NATed-IP-Address/m-p/92466#M10081</guid>
      <dc:creator>Abhas_Vijayvarg</dc:creator>
      <dc:date>2020-07-25T22:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN with NATed IP Address</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-NATed-IP-Address/m-p/92667#M10082</link>
      <description>&lt;P&gt;Connections will be initiated from the Internet to the gateway.&lt;BR /&gt;Since the gateway has only a private IP, something upstream has to do NAT to ensure traffic is received by the gateway.&lt;BR /&gt;If you can’t configure this, you might be able to reuse an existing public IP for this which is already routed through the gateway.&lt;BR /&gt;Can’t say for sure that will work.&lt;/P&gt;
&lt;P&gt;Regardless, Link Selection is needed no matter what here since you’re not terminating the VPN on an interface IP.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 00:06:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-NATed-IP-Address/m-p/92667#M10082</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-29T00:06:43Z</dc:date>
    </item>
  </channel>
</rss>

