<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT not working on GAIA in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246399#M12481</link>
    <description>&lt;P&gt;Really? One of the best sites ever &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Apr 2025 13:03:06 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2025-04-14T13:03:06Z</dc:date>
    <item>
      <title>NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246357#M12473</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;Have a interesting problem, I am missing something. Our configuration the Firewall R81.10. local managed. We have 2 Email Servers configured as a DAG, behind the Firewall and tried to NAT both to the same Public IP, the ending is .250, (Firewall has .251), When we send a email for example to &lt;A href="mailto:ping@mxtoolbox," target="_blank"&gt;ping@mxtoolbox,&lt;/A&gt;&amp;nbsp;it shows that the email is coming from .251. When we go to browser on either of the Email Servers and make a speedtest it shows up with the correct .250 Address.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously our problem is some Emails are refused since the .251 is no MX entry in the DNS. So how should we configure the NAT correctly?&lt;/P&gt;&lt;P&gt;Have added our NAT table DAG-Email contains both internal IP of Email Servers EX_NAT is public address .250 EX2019 and EX19-2 corresponds to the internal Email Servers.&lt;/P&gt;&lt;P&gt;All 3 NAT are clicked "Hide multiple sources behind the translated source addresses" as well as "Serve as an ARP Proxy for the original destination IP address".&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW we have a 3rd Email Server using NAT with .253 that works fine.&lt;/P&gt;&lt;P&gt;Would greatly appreciate some help with this, I obviously am missing something.&lt;/P&gt;&lt;P&gt;Thanks much&lt;/P&gt;&lt;P&gt;JJY&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 10:09:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246357#M12473</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2025-04-14T10:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246360#M12474</link>
      <description>&lt;P&gt;Could you share a pic of the NAt rules? Simply blur out the sensitive data&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 10:26:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246360#M12474</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-04-14T10:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246364#M12475</link>
      <description>&lt;P&gt;I thought I had added the .png&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="NAT.png" style="width: 200px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30205i6C9BDDC46AA67238/image-size/small?v=v2&amp;amp;px=200" role="button" title="NAT.png" alt="NAT.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 10:32:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246364#M12475</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2025-04-14T10:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246383#M12476</link>
      <description>&lt;P&gt;Just to make sure there is no connection that "stuck" somewhere, have you tried rebooting the fw?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 12:08:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246383#M12476</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-14T12:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246384#M12477</link>
      <description>&lt;P&gt;Thanks for support, but yes have rebooted a couple of times.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 12:11:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246384#M12477</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2025-04-14T12:11:23Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246387#M12478</link>
      <description>&lt;P&gt;K, just to make sure we got this right, do you have basic diagram of what exactly is supposed to be natted and how? I think that way, we can 100% ensure its right.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 12:15:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246387#M12478</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-14T12:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246395#M12479</link>
      <description>&lt;P&gt;Now I suggest you to do packet capture eg.: # fw monitor, and check what happening. Does the packet leave the CheckPoint, or stucks is somewhere, as Andy told.&lt;/P&gt;
&lt;P&gt;A little help for the syntax : &lt;A href="https://tcpdump101.com/" target="_blank"&gt;https://tcpdump101.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Maybe an fw ctl zdebug + drop | grep IP can be useful as well.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 12:49:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246395#M12479</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-04-14T12:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246396#M12480</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;Thank you for promoting my colleague's site, appreciated it mate! We gave it to few customers in the past when we would go on site to do work for them, I hope they still use it : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 12:55:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246396#M12480</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-14T12:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246399#M12481</link>
      <description>&lt;P&gt;Really? One of the best sites ever &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 13:03:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246399#M12481</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-04-14T13:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246402#M12482</link>
      <description>&lt;P&gt;O yea, he is super nice guy. Funny enough, he actually gave me R60 CCSA and CCSE training back in 2009 (makes me feel old lol). Im sure&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;knows him really well.&lt;/P&gt;
&lt;P&gt;These days, he is really busy, so he may update the site from time to time, but probably not as often as he used to. but, if you or anyone else has a feedback, Im sure he would be more than happy to look into whatever suggestions people have.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 13:06:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246402#M12482</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-14T13:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246435#M12483</link>
      <description>&lt;P&gt;We worked together for a hot minute, so yeah. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 17:54:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246435#M12483</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-14T17:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246453#M12484</link>
      <description>&lt;P&gt;I still think simple diagram would help us, just blur out any sensitive data.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 01:02:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246453#M12484</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-15T01:02:31Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246470#M12485</link>
      <description>&lt;P&gt;Thanks guys, I have attached a 'simple' diagram with just the relevant devices. Packets are sent, entire Emails are being sent just not with NAT, tried putting one of the Servers in as Server, but no difference&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;Jeff&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 07:52:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246470#M12485</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2025-04-15T07:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246491#M12486</link>
      <description>&lt;P&gt;Hi Jeff,&lt;/P&gt;
&lt;P&gt;K, so just to make sure I got this right (tx for the diagram btw, excellent), is it the case where 172.17 and .18 hosts are supposed to be natted to 88.x.x.x IPs respectively?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 10:59:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246491#M12486</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-15T10:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246493#M12487</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;Yes, acutally quite strange, the 2 Exchange servers are in a Microsoft DAG so both Servers contain all Mailboxes and both Send/Recieve Emails. Both Servers 172.17.0.6/7 should be NATed to 88.217.xx.250. When using the browser (HTTPS), to identify ip Address it shows on both Servers correctly 88.217.xx.250. However when sending Emails, (to help identify problem, presently only the .6 is used to send Emails), in the header it shows Email is coming from the 88.217xx.251, which is the IP Address of the Checkpoint. This of course does not correspond to SPF,DMARC, and DKIM. Have presently helped simply by adding the .251 Address as a mx. But this will not work long since it is not possible to create a DKIM for the Firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Internet settings for both under NAT the 'Do not hide internal networks behind this Internet connection' is not clicked . If it is clicked then the correct ip Address is used in sending Emails, (in other words works as should), however all other Servers can no longer connect to the Internet.&lt;/P&gt;&lt;P&gt;Hope this description is understandable :).&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 11:16:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246493#M12487</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2025-04-15T11:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246494#M12488</link>
      <description>&lt;P&gt;It is, yes, thanks! Hey, if you allow remote, I would love to do it and see if we can figure this out. Im in EST, which is GMT-4 I believe, so its 7.30 am here, I can do around 8.30 am my time, if that works?&lt;/P&gt;
&lt;P&gt;Let me know.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 11:26:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246494#M12488</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-15T11:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246496#M12489</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;Sure, so about 1hr? can send me an email &lt;A href="mailto:info@softwhere-it.com" target="_blank"&gt;info@softwhere-it.com&lt;/A&gt;&amp;nbsp;could give you direct access to FW or Remote up to you.&lt;/P&gt;&lt;P&gt;Greets,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 11:42:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246496#M12489</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2025-04-15T11:42:46Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246498#M12490</link>
      <description>&lt;P&gt;Are you free in about 15 mins? I can send you direct message here with zoom link if that works?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 11:48:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246498#M12490</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-15T11:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246500#M12491</link>
      <description>&lt;P&gt;Also emailed you via my personal gmail.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 11:59:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246500#M12491</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-15T11:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAT not working on GAIA</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246508#M12492</link>
      <description>&lt;P&gt;Yes, am available now, had to go to Mac's for some food, (if you can call it that!)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 12:19:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-not-working-on-GAIA/m-p/246508#M12492</guid>
      <dc:creator>Softwhere</dc:creator>
      <dc:date>2025-04-15T12:19:41Z</dc:date>
    </item>
  </channel>
</rss>

