<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Incoming Web Traffic Not Forwarding in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225395#M11319</link>
    <description>&lt;P&gt;better to provide two tcpdump, one from internal, one from external&lt;/P&gt;</description>
    <pubDate>Tue, 03 Sep 2024 02:04:19 GMT</pubDate>
    <dc:creator>garrod</dc:creator>
    <dc:date>2024-09-03T02:04:19Z</dc:date>
    <item>
      <title>Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225272#M11300</link>
      <description>&lt;P&gt;Good morning.&amp;nbsp; With a Spark 1575 locally managed runningU version R81.10.10 (996002945).&amp;nbsp; How can I get incoming web traffic to forward to a designated internal server?&amp;nbsp; I have a server object set as a web server using the default ports of 80 &amp;amp; 443 &amp;amp; Nginx installed on the internal Ubuntu 24.04 server.&amp;nbsp; Utiilizing this setup, no traffic gets forwarded &amp;amp; cannot see the incoming traffic while monitoring the security log.&amp;nbsp; If I set a secondary port - 8081 - it will work each &amp;amp; every time &amp;amp; can see the incoming traffic but, that requires having end users adding the :8081 to the web address.&amp;nbsp; I have went as far as adding manual firewall rules but to no avail.&amp;nbsp; How to correct?&amp;nbsp; Simple fix or have to contact TAC?&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 14:12:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225272#M11300</guid>
      <dc:creator>Jon_AK</dc:creator>
      <dc:date>2024-09-01T14:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225282#M11301</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/92542"&gt;@Jon_AK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the traffic flow?&lt;/P&gt;
&lt;P&gt;Internet -&amp;gt; Public IP &amp;gt; NAT &amp;gt; internal IP of the ubuntu?&lt;/P&gt;
&lt;P&gt;Ákos&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 17:04:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225282#M11301</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-01T17:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225285#M11302</link>
      <description>&lt;P&gt;Hopefully I understand your question correctly, let me know if I missed the boat...&lt;/P&gt;&lt;P&gt;Your traffic flow depiction is correct.&lt;/P&gt;&lt;P&gt;At the moment, the public IP is dynamic &amp;amp; hasn't changed in over a year but, I checked it to ensure it matched what is recoreded in our registrar's DNS recored.&lt;/P&gt;&lt;P&gt;NAT is set Hide behind the gateway &amp;amp; the internal IP address of the server the traffic is to route to is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 17:13:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225285#M11302</guid>
      <dc:creator>Jon_AK</dc:creator>
      <dc:date>2024-09-01T17:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225289#M11303</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/92542"&gt;@Jon_AK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Two things came into my mind:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Maybe tcp443 and tcp80 is a restricted port for the SMB appliances from outside, therefore the connection won't work for them, and work only for tcp8081.&lt;/LI&gt;
&lt;LI&gt;If we talk about reaching servers from outside, I use Static NAT setting.&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Configuring-NAT-Policy.htm" target="_self"&gt;&lt;EM&gt;Types of NAT Methods&lt;/EM&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Static:&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;The Security Gateway changes the source IP address of all connections from a source to the IP address your configure.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Notes:&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;When you configure Static NAT, the Security Gateway allows external traffic to access internal resources.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;If you enable this configuration in an object that represents one IP address (a Host object), then this gives you a one-to-one address translation.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;If you enable this configuration in an object that represents many IP addresses (a Network object, an Address Range object), then this gives you a many-to-one address translation.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The Security Gateway translates each internal IP address to a different external IP address.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;Important - The range of the translated IP addresses is the same as the range of the source IP addresses.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 17:24:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225289#M11303</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-01T17:24:01Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225290#M11304</link>
      <description>&lt;P&gt;Interesting.&amp;nbsp; I am still learning the functionality of the Spark 1575.&amp;nbsp; I was wondering if all incoming port 80 traffic was ignored by default.&amp;nbsp; I will certainly dive into this when I get back in a couple hours &amp;amp; will post back with my results.&amp;nbsp; Thanks you for the detailed explanation.... Old guys like me need a bit of "help" now &amp;amp; again &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 17:29:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225290#M11304</guid>
      <dc:creator>Jon_AK</dc:creator>
      <dc:date>2024-09-01T17:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225295#M11305</link>
      <description>&lt;P&gt;Akos, I reviewed the article along with the settings for this 1575.&amp;nbsp; Since this is a locallly manaaged device &amp;amp; does not have the corporate configuration interface, the configuration settings seem to be very limited with respect to the corporate interface.&amp;nbsp; I tried the static NAT address along with several variations of this &amp;amp; still cannot get this to answer incoming web traffic that is not specificallly bound for port other than 80.&amp;nbsp; 8081, 8086, 8080 all work first go around.&amp;nbsp; I do not see any other place in this interface for configuring a static NAT as shown in this screen capture&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="NATConfigScreen.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27466iCD2A3778721B1E62/image-size/large?v=v2&amp;amp;px=999" role="button" title="NATConfigScreen.png" alt="NATConfigScreen.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 23:07:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225295#M11305</guid>
      <dc:creator>Jon_AK</dc:creator>
      <dc:date>2024-09-01T23:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225296#M11306</link>
      <description>&lt;P&gt;In the advanced options for remote access their will be a setting for reserving the port for NAT and or changing the port for remote access to avoid conflicts.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 23:27:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225296#M11306</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-09-01T23:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225298#M11307</link>
      <description>&lt;P&gt;I'm afraid you're going to have to help me out here.&amp;nbsp; I'm failing to both find the setting you're indicating &amp;amp; why I would be changing a remote access setting to allow traffic to a web page.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 00:12:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225298#M11307</guid>
      <dc:creator>Jon_AK</dc:creator>
      <dc:date>2024-09-02T00:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225300#M11308</link>
      <description>&lt;P&gt;Device &amp;gt; Advanced &amp;gt; Advanced Settings (search for 443)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="443.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27467i3E1EEB3C4CC5D553/image-size/large?v=v2&amp;amp;px=999" role="button" title="443.jpg" alt="443.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 00:23:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225300#M11308</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-09-02T00:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225301#M11309</link>
      <description>&lt;P&gt;I found that but didn't make sense to me so I didn't change it first time around.&amp;nbsp; I changed it from its default value of 8443 to 80 but still no joy with website access.&amp;nbsp; Should have also included, I disabled the setting also but still no access.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 00:44:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225301#M11309</guid>
      <dc:creator>Jon_AK</dc:creator>
      <dc:date>2024-09-02T00:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225303#M11310</link>
      <description>&lt;P&gt;If you want 443 to work from outside you'll need to tick the box to "reserve" it else the remote access service of the appliance itself will absorb those connections.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 00:48:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225303#M11310</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-09-02T00:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225304#M11311</link>
      <description>&lt;P&gt;Appreciate your continued input for this Chris.&amp;nbsp; I am not trying to use HTTPS for the web page access, just plain jane HTTP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 00:50:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225304#M11311</guid>
      <dc:creator>Jon_AK</dc:creator>
      <dc:date>2024-09-02T00:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225305#M11312</link>
      <description>&lt;P&gt;Noted. To confirm nothing seen in tcpdump?&lt;/P&gt;
&lt;P&gt;Are you using wireless or bridge interfaces on this appliance...&lt;/P&gt;
&lt;P&gt;What value is returned when you run the following from the CLI (via SSH):&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;CODE&gt;fw ctl get int fwx_bridge_use_routing&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 01:54:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225305#M11312</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-09-02T01:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225306#M11313</link>
      <description>&lt;P&gt;No wireless or bridge.&amp;nbsp; The 1575 is the 1st demarc, no ISP provided modem to bridge.&amp;nbsp; As for inputting the cli command, I have no idea how to access that.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 01:20:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225306#M11313</guid>
      <dc:creator>Jon_AK</dc:creator>
      <dc:date>2024-09-02T01:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225307#M11314</link>
      <description>&lt;P&gt;To confirm are you seeing the connection redirected in the browser?&lt;/P&gt;
&lt;P&gt;For that command (possibly low likelihood / relevance), you'll need to connect via SSH or Serial Console into the appliance using a tool like PuTTy etc.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 02:04:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225307#M11314</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-09-02T02:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225309#M11315</link>
      <description>&lt;P&gt;No redirection, no action occurs.&amp;nbsp; Response from the requested command is:&amp;nbsp; fwx_bridge_use_routing = 2&amp;nbsp; Also, I modified the virtual server configuration file to reflect an ssl connection.&amp;nbsp; I get no response out of that either.&amp;nbsp; Thought that may help narrow down what may be the issue here.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 02:11:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225309#M11315</guid>
      <dc:creator>Jon_AK</dc:creator>
      <dc:date>2024-09-02T02:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225319#M11316</link>
      <description>&lt;P&gt;Hi, it seems this is the static NAT setting&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 07:35:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225319#M11316</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-02T07:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225324#M11317</link>
      <description>&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;Good to provide the tcpdump OR fw monitor, so that we can see if the traffic is being NATed correctly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 01:59:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225324#M11317</guid>
      <dc:creator>garrod</dc:creator>
      <dc:date>2024-09-03T01:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225346#M11318</link>
      <description>&lt;P&gt;tcpdump file is attached.&amp;nbsp; I set the IP to the static NAT in the server configuration.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 13:04:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225346#M11318</guid>
      <dc:creator>Jon_AK</dc:creator>
      <dc:date>2024-09-02T13:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: Incoming Web Traffic Not Forwarding</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225395#M11319</link>
      <description>&lt;P&gt;better to provide two tcpdump, one from internal, one from external&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 02:04:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Incoming-Web-Traffic-Not-Forwarding/m-p/225395#M11319</guid>
      <dc:creator>garrod</dc:creator>
      <dc:date>2024-09-03T02:04:19Z</dc:date>
    </item>
  </channel>
</rss>

