<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Site to Site VPN with DAIP Gateway and NAT hide not working in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246252#M12454</link>
    <description>&lt;P&gt;&lt;SPAN&gt;When trying to connect a DAIP VPN Gateway with NAT hide to the VPN VSX, no VPN tunnel can be established. In the files iked.elg and vpnd.elg I don't find a reason why this VPN tunnel cannot be established.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Check Point TAC told us that this is not working due to the fact that NAT hide changes the source port IKE from 500/udp to a high port and also NAT-T from 4500/4500 to a high port. Still the destination port remains correct.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;All other site to site VPN tunnels work fine. They all have a fix public IP address. Please help me to find the reason why this is not working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does anybody have experience with such a topology or even a setup which is working?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for your help.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Apr 2025 13:13:44 GMT</pubDate>
    <dc:creator>bbruelhart</dc:creator>
    <dc:date>2025-04-11T13:13:44Z</dc:date>
    <item>
      <title>Site to Site VPN with DAIP Gateway and NAT hide not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246252#M12454</link>
      <description>&lt;P&gt;&lt;SPAN&gt;When trying to connect a DAIP VPN Gateway with NAT hide to the VPN VSX, no VPN tunnel can be established. In the files iked.elg and vpnd.elg I don't find a reason why this VPN tunnel cannot be established.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The Check Point TAC told us that this is not working due to the fact that NAT hide changes the source port IKE from 500/udp to a high port and also NAT-T from 4500/4500 to a high port. Still the destination port remains correct.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;All other site to site VPN tunnels work fine. They all have a fix public IP address. Please help me to find the reason why this is not working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does anybody have experience with such a topology or even a setup which is working?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for your help.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 13:13:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246252#M12454</guid>
      <dc:creator>bbruelhart</dc:creator>
      <dc:date>2025-04-11T13:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with DAIP Gateway and NAT hide not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246254#M12455</link>
      <description>&lt;P&gt;Would you mind send debug files? Happy to review myself (you can also DM me, no problem). By the way, in my humble opinion, if dst port is unchanged, then you are fine, because source port literally would never matter, only destination one.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 13:22:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246254#M12455</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-11T13:22:12Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with DAIP Gateway and NAT hide not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246262#M12456</link>
      <description>&lt;P&gt;Hello Andy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your fast answer. That's what I thought as well that the source port would not matter but the engineers in the case insisted that it has to have the same source port for IKE and NAT-T.&amp;nbsp;&lt;BR /&gt;I will try to find the requested files and send them to you.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;On the central side I have a cluster of Quantum 26000 with a VSX for VPN connection and on the remote side I have a Quantum Spark 1575.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should that topology work at all?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 14:01:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246262#M12456</guid>
      <dc:creator>bbruelhart</dc:creator>
      <dc:date>2025-04-11T14:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with DAIP Gateway and NAT hide not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246264#M12457</link>
      <description>&lt;P&gt;That should be fine. Is it star community? Honestly, I still have hard time with understanding how same source port would need to be the same, but maybe someone else can confirm for sure.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 14:28:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246264#M12457</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-11T14:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with DAIP Gateway and NAT hide not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246339#M12465</link>
      <description>&lt;P&gt;Why do you use S2S for a DIAP GW? The reasonable choice would be to fall back to RAS VPN in this case. Did you try that?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 07:21:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246339#M12465</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-04-14T07:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with DAIP Gateway and NAT hide not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246345#M12466</link>
      <description>&lt;P&gt;Should work if the DAIP GW starts the VPN tunnel. DId read this &lt;A href="https://support.checkpoint.com/results/sk/sk167473" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk167473: Dynamically Assigned IP Address (&lt;STRONG&gt;DAIP&lt;/STRONG&gt;) Gateway FAQ&lt;/SPAN&gt;&lt;/A&gt;?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 08:18:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246345#M12466</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-04-14T08:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with DAIP Gateway and NAT hide not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246404#M12467</link>
      <description>&lt;P&gt;I was able to configure both, the dynamic gateway and the center side VSX, both on the same management server.&lt;/P&gt;&lt;P&gt;After allowing the ports FW1_ica_pull, FW1_ica_push, FW1_ica_services and FW1_log and defining the dynamic gateway's MAC address I was able to configure the SIC securely.&lt;/P&gt;&lt;P&gt;After that I could pull the prepared policy from the management server and then the VPN tunnel and the prepared policy was working.&lt;/P&gt;&lt;P&gt;Thanks again to Andy, the legend, for his support.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 13:12:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246404#M12467</guid>
      <dc:creator>bbruelhart</dc:creator>
      <dc:date>2025-04-14T13:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with DAIP Gateway and NAT hide not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246478#M12472</link>
      <description>&lt;P&gt;Why did you have to allow these ports ? Are they not covered by implied rules ?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 09:33:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246478#M12472</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-04-15T09:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with DAIP Gateway and NAT hide not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246518#M12500</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;BR /&gt;Now, I am confused. How would I define a RAS VPN then?&lt;BR /&gt;What object would I define in the SmartConsole for die DIAP gateway?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Beat&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 13:19:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246518#M12500</guid>
      <dc:creator>bbruelhart</dc:creator>
      <dc:date>2025-04-15T13:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with DAIP Gateway and NAT hide not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246520#M12501</link>
      <description>&lt;P&gt;The DIAP gateway is in the Internet and needs to communicate with the Check Point management server which is behind the Internet firewall. So, for the SIC I allowed FW1_ica_service, FW1_ica_pull, FW1_ica_push, FW1_log and CPD to th public (NAT) object of the managment server. Only with the implied rules this did not work for me.&lt;BR /&gt;Is there another way to do that?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 13:34:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246520#M12501</guid>
      <dc:creator>bbruelhart</dc:creator>
      <dc:date>2025-04-15T13:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN with DAIP Gateway and NAT hide not working</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246535#M12502</link>
      <description>&lt;P&gt;I can not verify that - this had not been a need for non-VSX GAiA GWs / SMS with older SMBs. But as it is working that seems the correct way to do it &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 14:55:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Site-to-Site-VPN-with-DAIP-Gateway-and-NAT-hide-not-working/m-p/246535#M12502</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-04-15T14:55:10Z</dc:date>
    </item>
  </channel>
</rss>

