<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help in understanding NAT in relation to mobile VPN traffic in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226983#M3194</link>
    <description>&lt;P&gt;Exactly!&amp;nbsp; I was able to ping 10.10.10.100 but not .99&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Sep 2024 18:59:58 GMT</pubDate>
    <dc:creator>Joe_Kanaszka</dc:creator>
    <dc:date>2024-09-17T18:59:58Z</dc:date>
    <item>
      <title>Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226980#M3191</link>
      <description>&lt;P&gt;HI all.&lt;/P&gt;
&lt;P&gt;I changed the mask on the "CP_default_Office_Mode_addresses_pool" network group from /25 to /26. to make room for 4 nets.&lt;/P&gt;
&lt;P&gt;My "CP default Office Mode address pool" range changed from 10.10.10.1-126 to 10.10.10.65 - 126.&lt;/P&gt;
&lt;P&gt;(The plan was to reserve one of the nets for use in the ipassignement.conf file.&amp;nbsp; We need a handful of users to always get the same static ip address when WFH.)&lt;/P&gt;
&lt;P&gt;I created a new network object that contained IPs in the range of 10.10.10.1-62.&amp;nbsp; I created my ipassignment.conf file and assigned 10 users with static ips from this new IP range.&lt;/P&gt;
&lt;P&gt;I made sure to add this new group to my remote access encryption domain&lt;/P&gt;
&lt;P&gt;We tested the new static IPs while signed into the mobile VPN and all seemed fine.&amp;nbsp; However, we were not able to access our CIFS file share server.&amp;nbsp; We couldn't ping it...&lt;/P&gt;
&lt;P&gt;I was able to access other resources on my remote network.&lt;/P&gt;
&lt;P&gt;I checked DNS - no issues.&amp;nbsp; No double entries.&lt;/P&gt;
&lt;P&gt;When I ran fw monitor while pinging the CIFS server I was not receiving any ICMP replies back...&lt;/P&gt;
&lt;P&gt;After checking the new network object I created I noticed that I did not have "Add automatic address translation rules" "Hide behind the gateway" checked.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After checking the option to use "hide NAT"&amp;nbsp; and re-logging into the mobile access VPN, I was able to access my CIFS server.&lt;/P&gt;
&lt;P&gt;Now for my question:&lt;/P&gt;
&lt;P&gt;Why would I be able to ping other machines on the same network but not access this one IP until I enabled Hide NAT?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 13:01:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226980#M3191</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2024-09-18T13:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226981#M3192</link>
      <description>&lt;P&gt;Valid question, for sure. I know by default, OM net is set to hide behind gw for nat, thats been like that probaly since the begging of Check Point. Now, just to make sure, are you saying, say IP 10.10.10.100 was fine to access WITHOUT nat, but then say 10.10.10.99 was NOT?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 18:42:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226981#M3192</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-17T18:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226982#M3193</link>
      <description>&lt;P&gt;Could be a lot of reasons. Think about routing on network, servers etc.&lt;/P&gt;
&lt;P&gt;Or even ACL that has been set on the CIFS server. The server does probably not know where to route the real ip or blocks it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe it routes it wrong end it ends on the wrong interface of the firewall (then you get anti-spoofing messages or out of state)&lt;/P&gt;
&lt;P&gt;Based on the info you shared it is very unlikely that it was a firewall problem and therefore I cannot help further.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 18:42:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226982#M3193</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-09-17T18:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226983#M3194</link>
      <description>&lt;P&gt;Exactly!&amp;nbsp; I was able to ping 10.10.10.100 but not .99&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 18:59:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226983#M3194</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2024-09-17T18:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226984#M3195</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Based on the info you shared it is very unlikely that it was a firewall problem and therefore I cannot help further.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp; Well - it sure does seem like a FW problem being that right after I enabled "Hide NAT" I was able to ping the server....&lt;/P&gt;
&lt;DIV class="UserSignature lia-message-signature"&gt;-------&lt;/DIV&gt;</description>
      <pubDate>Tue, 17 Sep 2024 19:05:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226984#M3195</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2024-09-17T19:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226985#M3196</link>
      <description>&lt;P&gt;Got it. Ok, so not sure if you can replicate the issue, but if you could, I would run below and compare.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;-traceroute (see where it fails)&lt;/P&gt;
&lt;P&gt;-from the fw, ip r g ip_address -&amp;gt; example : ip r g 10.10.10.99&lt;/P&gt;
&lt;P&gt;-tcpdump on the fw for affected ip, ie tcpdump -enni any host 10.10.10.99&lt;/P&gt;
&lt;P&gt;-maybe quick zdebug to see if anything gets dropped -&amp;gt; fw ctl zdebug + drop | grep 10.10.10.99&lt;/P&gt;
&lt;P&gt;-any logs filtering for that IP&lt;/P&gt;
&lt;P&gt;Thats all I can think off for now bro. Other than that, Im afriad not much we can offer unless problem is there, so it can be troubleshot.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 19:06:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226985#M3196</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-17T19:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226986#M3197</link>
      <description>&lt;P&gt;Dont worry brother, no matter the issue, we can ALWAYS help, or at least guide you in the right direction.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 19:07:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226986#M3197</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-17T19:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226987#M3198</link>
      <description>&lt;P&gt;With NAT you change the outgoing IP. Not the firewall fault the that the CIFS server is not sending a ping reply to the real ip.&lt;/P&gt;
&lt;P&gt;Is free advise here if you don't want to follow fine by me.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 19:17:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226987#M3198</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-09-17T19:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226988#M3199</link>
      <description>&lt;P&gt;On a side note:&lt;/P&gt;
&lt;P&gt;What is the # ip r g "ip address" command?&amp;nbsp; Never seen that although I see what it does.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 19:31:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226988#M3199</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2024-09-17T19:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226989#M3200</link>
      <description>&lt;P&gt;Just shows you the path fw uses to get to whatever IP bro.&lt;/P&gt;
&lt;P&gt;example in my lab.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@CP-GW:0]# ip r g 8.8.8.8&lt;BR /&gt;8.8.8.8 via 172.16.10.1 dev eth0 src 172.16.10.249&lt;BR /&gt;cache&lt;BR /&gt;[Expert@CP-GW:0]#&lt;/P&gt;
&lt;P&gt;[Expert@CP-GW:0]# route&lt;BR /&gt;Kernel IP routing table&lt;BR /&gt;Destination Gateway Genmask Flags Metric Ref Use Iface&lt;BR /&gt;default 172.16.10.1 0.0.0.0 UG 0 0 0 eth0&lt;BR /&gt;172.16.10.0 * 255.255.255.0 U 0 0 0 eth0&lt;BR /&gt;172.31.10.0 * 255.255.255.0 U 0 0 0 eth1&lt;BR /&gt;192.168.10.0 * 255.255.254.0 U 0 0 0 eth2&lt;BR /&gt;[Expert@CP-GW:0]#&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 19:33:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226989#M3200</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-17T19:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226990#M3201</link>
      <description>&lt;P&gt;Cool.&amp;nbsp; Thank u.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 19:41:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/226990#M3201</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2024-09-17T19:41:14Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227017#M3202</link>
      <description>&lt;P&gt;Np, message me any time if you want to do remote session.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 23:50:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227017#M3202</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-17T23:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227021#M3203</link>
      <description>&lt;P&gt;With an automatic Hide NAT, the Firewall basically delivers the communication using the Firewall's own IP. We need to analyze who the Default Gateway of your CIFS server is, because it seems that it is not the Firewall that you are connected to via Remote Access VPN, therefore, it does not know the Office Mode network of your Firewall.&lt;/P&gt;&lt;P&gt;Log in to your CIFS server and check if it can ping the real IP that was assigned to you in Office Mode. The communication worked, because the Default Gateway of your CIFS server was able to communicate with the Firewall that you are connected to via Remote Access, but for some reason it cannot communicate with your real Office Mode IP.&lt;/P&gt;&lt;P&gt;In other words, since the Check Point Firewall stores the communications in the NAT table, when the packet is returned to the Firewall's IP, it knows your Office Mode and delivers the packet to you (with Automatic Hide NAT enabled), but the IP that arrives at the CIFS server is the Firewall's IP.&lt;/P&gt;&lt;P&gt;If the CIFS server is behind another Firewall, make a route on this Firewall, something like {If Destination = Office Mode, then Default Gateway = Your Office Mode Firewall IP}.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 04:55:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227021#M3203</guid>
      <dc:creator>fabionfsc</dc:creator>
      <dc:date>2024-09-18T04:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227022#M3204</link>
      <description>&lt;P&gt;One thing, your office mode range shouldn't be in your VPN encryption domain. The encryption domain is to contain the on-prem subnets and networks that you want to allow VPN users to get to, not the VPN users themselves. I'm not suggesting that this is the cause of the problem, just a note on your comment there. It should however it something that the internal network devices will route back to the gateway if you don't have the NAT enabled on it.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 05:15:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227022#M3204</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-09-18T05:15:47Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227072#M3205</link>
      <description>&lt;P&gt;This makes sense.&amp;nbsp; Thank you so much fabionfsc!&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 11:26:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227072#M3205</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2024-09-18T11:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227073#M3206</link>
      <description>&lt;P&gt;Thank you so much Rock!&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 11:28:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227073#M3206</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2024-09-18T11:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227074#M3207</link>
      <description>&lt;P&gt;Thank you emmap&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 11:28:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227074#M3207</guid>
      <dc:creator>Joe_Kanaszka</dc:creator>
      <dc:date>2024-09-18T11:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in understanding NAT in relation to mobile VPN traffic</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227076#M3208</link>
      <description>&lt;P&gt;Fantastic explanation&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/105142"&gt;@fabionfsc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2024 12:00:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Need-help-in-understanding-NAT-in-relation-to-mobile-VPN-traffic/m-p/227076#M3208</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-18T12:00:01Z</dc:date>
    </item>
  </channel>
</rss>

