<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 1450 Appliance @ Branch Office Question in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1450-Appliance-Branch-Office-Question/m-p/6060#M103</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi - I am setting up 1450 appliances at a couple of branch offices, but I am not sure what my best approach is for configuring them to support our environment properly; Here is a basic proposed setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/58424_snip_20170906163923.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;I am having some trouble since I need the gateway to not NAT and not block all incoming traffic by default, as traffic from the CorporateLAN to the BranchOfficeLAN (and vice versa) is common. I can't seem to configure the firewall service to deal with this so far - and I am&amp;nbsp;surely just being dense &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;- but if I disable the firewall and NAT, traffic passes as I would want. However that defeats some of the purpose, and&amp;nbsp;I would hope to configure an Internet connection (using the WAN port) and just create my policy manually. I seem to be stuck though with an all or nothing config...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice is greatly appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Sep 2017 21:54:06 GMT</pubDate>
    <dc:creator>David_Levine</dc:creator>
    <dc:date>2017-09-06T21:54:06Z</dc:date>
    <item>
      <title>1450 Appliance @ Branch Office Question</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1450-Appliance-Branch-Office-Question/m-p/6060#M103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi - I am setting up 1450 appliances at a couple of branch offices, but I am not sure what my best approach is for configuring them to support our environment properly; Here is a basic proposed setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/58424_snip_20170906163923.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;I am having some trouble since I need the gateway to not NAT and not block all incoming traffic by default, as traffic from the CorporateLAN to the BranchOfficeLAN (and vice versa) is common. I can't seem to configure the firewall service to deal with this so far - and I am&amp;nbsp;surely just being dense &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;- but if I disable the firewall and NAT, traffic passes as I would want. However that defeats some of the purpose, and&amp;nbsp;I would hope to configure an Internet connection (using the WAN port) and just create my policy manually. I seem to be stuck though with an all or nothing config...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice is greatly appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Sep 2017 21:54:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1450-Appliance-Branch-Office-Question/m-p/6060#M103</guid>
      <dc:creator>David_Levine</dc:creator>
      <dc:date>2017-09-06T21:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: 1450 Appliance @ Branch Office Question</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1450-Appliance-Branch-Office-Question/m-p/6061#M104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm pretty sure you can achieve this with manual NAT rules.&lt;/P&gt;&lt;P&gt;What NAT rules did you try?&lt;/P&gt;&lt;P&gt;Note this would also imply turning "Off" the Outgoing traffic NAT option, which can be recreated with manual NAT rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/58435_pastedImage_1.png" style="width: 620px; height: 312px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Sep 2017 20:17:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1450-Appliance-Branch-Office-Question/m-p/6061#M104</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-07T20:17:20Z</dc:date>
    </item>
  </channel>
</rss>

