<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't use groups with exclusion in NAT rules in R80? in SmartMove</title>
    <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/104255#M262</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2480"&gt;@Meital_Natanson&lt;/a&gt;&amp;nbsp;is there a way to test NAT rule matching from the CLI gateway similar to &lt;STRONG&gt;fw up_execute&lt;/STRONG&gt; for the Firewall/Network policy layer?&lt;/P&gt;</description>
    <pubDate>Thu, 03 Dec 2020 19:25:41 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2020-12-03T19:25:41Z</dc:date>
    <item>
      <title>Can't use groups with exclusion in NAT rules in R80?</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/77039#M251</link>
      <description>&lt;P&gt;In R80 can you not use groups with exclusion in NAT rules?&lt;/P&gt;&lt;P&gt;In a ruleset imported from R77 - where it has verified OK for years - am getting multiple verification errors:&lt;/P&gt;&lt;P&gt;Invalid Object 'XXXXX' in Original Source of Address Translation Rule 195. The valid objects are: host, gateway, network, address range and router.&lt;/P&gt;&lt;P&gt;The original source in that rule is a group with exclusion. Is that no longer supported?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 03:00:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/77039#M251</guid>
      <dc:creator>mhurst</dc:creator>
      <dc:date>2020-03-04T03:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use groups with exclusion in NAT rules in R80?</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/77040#M252</link>
      <description>&lt;P&gt;The valid objects are: host, gateway, network, address range and router.&lt;/P&gt;&lt;P&gt;Groups are not listed as valid objects at all in that verify message.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 03:07:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/77040#M252</guid>
      <dc:creator>mhurst</dc:creator>
      <dc:date>2020-03-04T03:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use groups with exclusion in NAT rules in R80?</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/77049#M254</link>
      <description>This was never formally supported.&lt;BR /&gt;The fact that it worked at all in prior releases is considered a bug that has since been fixed.&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97246" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97246&lt;/A&gt;</description>
      <pubDate>Wed, 04 Mar 2020 03:44:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/77049#M254</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-04T03:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use groups with exclusion in NAT rules in R80?</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/77054#M255</link>
      <description>&lt;P&gt;Thanks for the prompt response.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 04:08:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/77054#M255</guid>
      <dc:creator>mhurst</dc:creator>
      <dc:date>2020-03-04T04:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use groups with exclusion in NAT rules in R80?</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/77069#M256</link>
      <description>&lt;P&gt;It is unfortunate this was categorised as a bug as it is useful functionality.&lt;/P&gt;&lt;P&gt;Applying a NAT rule to a set of things except for a subset of those things is required sometimes.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 07:12:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/77069#M256</guid>
      <dc:creator>mhurst</dc:creator>
      <dc:date>2020-03-04T07:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use groups with exclusion in NAT rules in R80?</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/77146#M257</link>
      <description>Understand that it is useful, but you can achieve a similar result with additional "no NAT" rules.</description>
      <pubDate>Wed, 04 Mar 2020 15:51:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/77146#M257</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-04T15:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use groups with exclusion in NAT rules in R80?</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/79370#M258</link>
      <description>&lt;P&gt;I try this with our VPN addresses to and internal segment of our LAN and after I push policy I can no longer ping the network the destination network...does anyone have thoughts on that.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 15:15:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/79370#M258</guid>
      <dc:creator>Lhouse</dc:creator>
      <dc:date>2020-03-23T15:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use groups with exclusion in NAT rules in R80?</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/103279#M259</link>
      <description>&lt;P&gt;But if you use SmartMove tool (sk97246) for Juniper to Check Point conversion, it will happily create NAT rules using groups with exclusion; I think if you decided it's a bug in one place you should not use it in another as a feature (otherwise this tool is very handy, btw, thanks).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 16:25:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/103279#M259</guid>
      <dc:creator>amoruck</dc:creator>
      <dc:date>2020-11-25T16:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use groups with exclusion in NAT rules in R80?</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/103632#M260</link>
      <description>&lt;P&gt;That might be a bug in the SmartMove tool.&lt;BR /&gt;Paging&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1705"&gt;@yael_haker&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I'm actually curious now if rules with negated objects in NAT rules works in R81, since we made major changes to the NAT policy in this version.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 04:26:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/103632#M260</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-30T04:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use groups with exclusion in NAT rules in R80?</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/104237#M261</link>
      <description>&lt;P&gt;No. In R81, NAT supports domain objects, security zones, updatable objects, access roles, data centers and hit count.&lt;/P&gt;
&lt;P&gt;But not negate objects / group with exclusions.&lt;/P&gt;
&lt;P&gt;As you wrote before, it can be achieved using no NAT rule.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 16:38:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/104237#M261</guid>
      <dc:creator>Meital_Natanson</dc:creator>
      <dc:date>2020-12-03T16:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use groups with exclusion in NAT rules in R80?</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/104255#M262</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2480"&gt;@Meital_Natanson&lt;/a&gt;&amp;nbsp;is there a way to test NAT rule matching from the CLI gateway similar to &lt;STRONG&gt;fw up_execute&lt;/STRONG&gt; for the Firewall/Network policy layer?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 19:25:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/104255#M262</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-12-03T19:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use groups with exclusion in NAT rules in R80?</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/104630#M263</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp; - no such option.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 08:51:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/104630#M263</guid>
      <dc:creator>Meital_Natanson</dc:creator>
      <dc:date>2020-12-08T08:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can't use groups with exclusion in NAT rules in R80?</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/104759#M264</link>
      <description>&lt;P&gt;If there are issues with SmartMove - please contact us at &lt;A href="mailto:sc@checkpoint.com" target="_blank"&gt;sc@checkpoint.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;We will appreciate to get a copy of the config file in order to address this issue&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 10:59:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Can-t-use-groups-with-exclusion-in-NAT-rules-in-R80/m-p/104759#M264</guid>
      <dc:creator>Ofir_Shikolski</dc:creator>
      <dc:date>2020-12-09T10:59:28Z</dc:date>
    </item>
  </channel>
</rss>

