<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CGNAT Is not working on secondary WAN interface in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CGNAT-Is-not-working-on-secondary-WAN-interface/m-p/225135#M11298</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/70231"&gt;@eliaskoudounas&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The /31 mask is strange. It contains only network address and broadcast address. No usable IP (host) are in this subnet.&lt;/P&gt;
&lt;TABLE class="cinfoT"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;IP Address:&lt;/TD&gt;
&lt;TD&gt;10.0.1.0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Network Address:&lt;/TD&gt;
&lt;TD&gt;10.0.1.0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Usable Host IP Range:&lt;/TD&gt;
&lt;TD&gt;NA&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Broadcast Address:&lt;/TD&gt;
&lt;TD&gt;10.0.1.1&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Total Number of Hosts:&lt;/TD&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Number of Usable Hosts:&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;0&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Subnet Mask:&lt;/TD&gt;
&lt;TD&gt;255.255.255.254&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
    <pubDate>Fri, 30 Aug 2024 13:28:39 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2024-08-30T13:28:39Z</dc:date>
    <item>
      <title>CGNAT Is not working on secondary WAN interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CGNAT-Is-not-working-on-secondary-WAN-interface/m-p/225103#M11296</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;I come across a problem on current installation with an SMB Device.More precise:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Quantum Spark 1600 Appliance version R81.10.10 (996002945).&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;There is two wan interface on on DMZ with IP x.x.x.x/28 and the other on the WAN interface with IP y.y.y.y.y/31.&lt;/P&gt;&lt;P&gt;The SD-WAN Functionality is active and traffic from internal client can be redirected based on policy protocols etc, and that's support some core functionality for the network(traffic shaping).&lt;/P&gt;&lt;P&gt;The problem is on NATting service outside the LAN.&lt;/P&gt;&lt;P&gt;While using the DMZ interface with gateway IP on the network x.x.x.x/28&amp;nbsp; which include IPs provided by the ISP on the same range x.x.x.x/28 everything is working as expected.&lt;/P&gt;&lt;P&gt;When using the WAN interface with gateway IP is on this network y.y.y.y.y/31 the provided IPs from the other ISP is on another network z.z.z.z/30 and NAT rules doesn't seem to work despite giving the internal client the SD-SAN policy to use routes from the second interface y.y.y.y.y/31. Also i followed this guidance&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk114531" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk114531&lt;/A&gt; to configure proxy arp for all the network with the according MAC address of the interfaces and nothing seems to work.&lt;/P&gt;&lt;P&gt;The only way that the NAT worked is only when&amp;nbsp; a static rule on the routing table was created and configured with the next hop to be on the secondary interface here is an example.&lt;/P&gt;&lt;TABLE cellspacing="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Any&lt;/TD&gt;&lt;TD&gt;internal-client/32&lt;/TD&gt;&lt;TD&gt;Any&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;Secondary (WAN)&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Static(PBR)&lt;/TD&gt;&lt;TD&gt;60&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have anyone had any similar situation on an SMB appliance, the problem is that this solution is not fitting when you need to configure many internal servers and need to add static routing for each one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 09:09:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CGNAT-Is-not-working-on-secondary-WAN-interface/m-p/225103#M11296</guid>
      <dc:creator>eliaskoudounas</dc:creator>
      <dc:date>2024-08-30T09:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: CGNAT Is not working on secondary WAN interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CGNAT-Is-not-working-on-secondary-WAN-interface/m-p/225135#M11298</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/70231"&gt;@eliaskoudounas&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The /31 mask is strange. It contains only network address and broadcast address. No usable IP (host) are in this subnet.&lt;/P&gt;
&lt;TABLE class="cinfoT"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;IP Address:&lt;/TD&gt;
&lt;TD&gt;10.0.1.0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Network Address:&lt;/TD&gt;
&lt;TD&gt;10.0.1.0&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Usable Host IP Range:&lt;/TD&gt;
&lt;TD&gt;NA&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Broadcast Address:&lt;/TD&gt;
&lt;TD&gt;10.0.1.1&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Total Number of Hosts:&lt;/TD&gt;
&lt;TD&gt;2&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;Number of Usable Hosts:&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;0&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Subnet Mask:&lt;/TD&gt;
&lt;TD&gt;255.255.255.254&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 13:28:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CGNAT-Is-not-working-on-secondary-WAN-interface/m-p/225135#M11298</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-30T13:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: CGNAT Is not working on secondary WAN interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CGNAT-Is-not-working-on-secondary-WAN-interface/m-p/225413#M11323</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you for you time.&lt;/P&gt;&lt;P&gt;The ISP provide me with this network on our example will be something like that&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="197.967px" height="24px"&gt;IP Address:&lt;/TD&gt;&lt;TD width="123.7px" height="24px"&gt;172.132.125.32&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="197.967px" height="24px"&gt;Network Address:&lt;/TD&gt;&lt;TD width="123.7px" height="24px"&gt;172.28.125.32/31&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="197.967px" height="24px"&gt;Usable Host IP Range:&lt;/TD&gt;&lt;TD width="123.7px" height="24px"&gt;172.132.125.32&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="197.967px" height="24px"&gt;Broadcast Address:&lt;/TD&gt;&lt;TD width="123.7px" height="24px"&gt;172.132.125.33&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="197.967px" height="24px"&gt;Total Number of Hosts:&lt;/TD&gt;&lt;TD width="123.7px" height="24px"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="197.967px" height="24px"&gt;&lt;STRONG&gt;Number of Usable Hosts:&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="123.7px" height="24px"&gt;&lt;STRONG&gt;1&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="197.967px" height="24px"&gt;Subnet Mask:&lt;/TD&gt;&lt;TD width="123.7px" height="24px"&gt;255.255.255.254&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second ISP internet connection is currently active and working, thus routing internal traffic and nat is also accessible when i enable the static route&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 07:54:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CGNAT-Is-not-working-on-secondary-WAN-interface/m-p/225413#M11323</guid>
      <dc:creator>eliaskoudounas</dc:creator>
      <dc:date>2024-09-03T07:54:24Z</dc:date>
    </item>
  </channel>
</rss>

