<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic [SASE] connection NATed in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SASE-connection-NATed/m-p/246276#M1133</link>
    <description>&lt;P&gt;Hello everyone!&lt;/P&gt;&lt;P&gt;In the scenario where we have SASE using the Wireguard connector, we have observed that the connection IP for accessing applications is not from the SASE client but from the connect, that is, the connection is NATed. The question is, how can we make the user connection arrive with the connection IP in the application? Reason: in this scenario, security control in the applications is done by connection IP.&lt;/P&gt;&lt;P&gt;Below is the current scenario.&lt;/P&gt;&lt;P&gt;SASE client network: 10.17.4.0/22&lt;BR /&gt;On-premise client network: 10.0.250.0/23, 172.16.0.0/12 and 192.168.0.0/16&lt;/P&gt;&lt;P&gt;In the scenario where I use the IPSec VPN connector, would it be possible to meet this requirement?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Fri, 11 Apr 2025 18:49:43 GMT</pubDate>
    <dc:creator>eltonsimoes</dc:creator>
    <dc:date>2025-04-11T18:49:43Z</dc:date>
    <item>
      <title>[SASE] connection NATed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SASE-connection-NATed/m-p/246276#M1133</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;&lt;P&gt;In the scenario where we have SASE using the Wireguard connector, we have observed that the connection IP for accessing applications is not from the SASE client but from the connect, that is, the connection is NATed. The question is, how can we make the user connection arrive with the connection IP in the application? Reason: in this scenario, security control in the applications is done by connection IP.&lt;/P&gt;&lt;P&gt;Below is the current scenario.&lt;/P&gt;&lt;P&gt;SASE client network: 10.17.4.0/22&lt;BR /&gt;On-premise client network: 10.0.250.0/23, 172.16.0.0/12 and 192.168.0.0/16&lt;/P&gt;&lt;P&gt;In the scenario where I use the IPSec VPN connector, would it be possible to meet this requirement?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 18:49:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SASE-connection-NATed/m-p/246276#M1133</guid>
      <dc:creator>eltonsimoes</dc:creator>
      <dc:date>2025-04-11T18:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: [SASE] connection NATed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SASE-connection-NATed/m-p/246432#M1134</link>
      <description>&lt;P&gt;I believe this is expected behavior when using the Wireguard connector.&lt;BR /&gt;IPsec should work better in this regard.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 17:50:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SASE-connection-NATed/m-p/246432#M1134</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-14T17:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: [SASE] connection NATed</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SASE-connection-NATed/m-p/246450#M1135</link>
      <description>&lt;P&gt;Yep, as phoneboy said, you're seeing the expected result.&amp;nbsp; We tried that method and found it to be untenable, so we just added ipsec tunnels to all on-prem gateway and now the actual client IP is exposed to the onprem app.&amp;nbsp; hth&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 19:38:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SASE-connection-NATed/m-p/246450#M1135</guid>
      <dc:creator>D_TK</dc:creator>
      <dc:date>2025-04-14T19:38:30Z</dc:date>
    </item>
  </channel>
</rss>

