<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Quantum Spark NAT rule issue in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-NAT-rule-issue/m-p/201179#M10024</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am having a problem with a simple static NAT rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;The NAT rule&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original Source&lt;/STRONG&gt; : 88.176.93.245&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original Destination&lt;/STRONG&gt; : 37.58.232.192 (Gateway public IP)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original Service&lt;/STRONG&gt; : TCP 5000&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Translated Source&lt;/STRONG&gt; : Original&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Translated Destination&lt;/STRONG&gt; : 192.168.20.11 (internal device)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Translated Service&lt;/STRONG&gt; : Original&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;The related security rule&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Source&lt;/STRONG&gt; : 88.176.93.245&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Destination&lt;/STRONG&gt; : 37.58.232.192&amp;nbsp;(Gateway public IP)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Service&lt;/STRONG&gt; : TCP 5000&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt; : Allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The routing table (directly connected)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Destination | Source | Service | Next Hop | Metric | Protocol&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;192.168.20.0/24 | Any | Any | LAN10.20 | 0 | Directly Connected&lt;/P&gt;&lt;P&gt;37.58.224.0/24 | Any | Any | WAN12 | 0 | Directly Connected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I test from IP 88.176.93.245 to 37.58.232.192 on TCP port 5000 :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT color="#339966"&gt;I can see in the logs that the traffic is arriving on the gateway : 88.176.93.245 --&amp;gt; 37.58.232.192 on TCP 5000 --&amp;gt; Accept&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#FF0000"&gt;But the NAT rule does not apply : nothing on 37.58.232.192 --&amp;gt;&amp;nbsp;192.168.20.11&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the log&amp;nbsp;88.176.93.245 to 37.58.232.192 on TCP port 5000&amp;nbsp;I see different things that appeal to me :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;NAT rule number : 6 --&amp;gt; OK&lt;/LI&gt;&lt;LI&gt;Inzone : External --&amp;gt; OK&lt;/LI&gt;&lt;LI&gt;Out-Zone : External --&amp;gt; ????&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have an idea please?&lt;/P&gt;&lt;P&gt;thank you in advance for your help !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Dec 2023 10:51:52 GMT</pubDate>
    <dc:creator>nadsystems</dc:creator>
    <dc:date>2023-12-20T10:51:52Z</dc:date>
    <item>
      <title>Quantum Spark NAT rule issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-NAT-rule-issue/m-p/201179#M10024</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am having a problem with a simple static NAT rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;The NAT rule&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original Source&lt;/STRONG&gt; : 88.176.93.245&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original Destination&lt;/STRONG&gt; : 37.58.232.192 (Gateway public IP)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Original Service&lt;/STRONG&gt; : TCP 5000&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Translated Source&lt;/STRONG&gt; : Original&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Translated Destination&lt;/STRONG&gt; : 192.168.20.11 (internal device)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Translated Service&lt;/STRONG&gt; : Original&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;The related security rule&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Source&lt;/STRONG&gt; : 88.176.93.245&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Destination&lt;/STRONG&gt; : 37.58.232.192&amp;nbsp;(Gateway public IP)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Service&lt;/STRONG&gt; : TCP 5000&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Action&lt;/STRONG&gt; : Allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The routing table (directly connected)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Destination | Source | Service | Next Hop | Metric | Protocol&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;192.168.20.0/24 | Any | Any | LAN10.20 | 0 | Directly Connected&lt;/P&gt;&lt;P&gt;37.58.224.0/24 | Any | Any | WAN12 | 0 | Directly Connected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I test from IP 88.176.93.245 to 37.58.232.192 on TCP port 5000 :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT color="#339966"&gt;I can see in the logs that the traffic is arriving on the gateway : 88.176.93.245 --&amp;gt; 37.58.232.192 on TCP 5000 --&amp;gt; Accept&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT color="#FF0000"&gt;But the NAT rule does not apply : nothing on 37.58.232.192 --&amp;gt;&amp;nbsp;192.168.20.11&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the log&amp;nbsp;88.176.93.245 to 37.58.232.192 on TCP port 5000&amp;nbsp;I see different things that appeal to me :&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;NAT rule number : 6 --&amp;gt; OK&lt;/LI&gt;&lt;LI&gt;Inzone : External --&amp;gt; OK&lt;/LI&gt;&lt;LI&gt;Out-Zone : External --&amp;gt; ????&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have an idea please?&lt;/P&gt;&lt;P&gt;thank you in advance for your help !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 10:51:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-NAT-rule-issue/m-p/201179#M10024</guid>
      <dc:creator>nadsystems</dc:creator>
      <dc:date>2023-12-20T10:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark NAT rule issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-NAT-rule-issue/m-p/201190#M10025</link>
      <description>&lt;P&gt;What do you want to achieve here ? Why not define &lt;FONT color="#FF0000"&gt;192.168.20.11&lt;/FONT&gt; as a webserver ?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 13:51:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-NAT-rule-issue/m-p/201190#M10025</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-12-20T13:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark NAT rule issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-NAT-rule-issue/m-p/201197#M10026</link>
      <description>&lt;P&gt;To confirm you don't see&amp;nbsp;&lt;SPAN&gt;37.58.232.X in the routing table?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Also which firmware version &amp;amp; build is the spark appliance installed with and is it centrally or locally nmanaged?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 21:28:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-NAT-rule-issue/m-p/201197#M10026</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-20T21:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: Quantum Spark NAT rule issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-NAT-rule-issue/m-p/201209#M10028</link>
      <description>&lt;P&gt;For NAPT involving the Security Gateway IP, you need to create a Server object instead of a NAT rule.&lt;BR /&gt;This is done via Users and Objects &amp;gt; Network Resources &amp;gt; Servers in the WebUI.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2023 16:14:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Quantum-Spark-NAT-rule-issue/m-p/201209#M10028</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-20T16:14:10Z</dc:date>
    </item>
  </channel>
</rss>

