<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: this is very urgent, need help with natting in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/this-is-very-urgent-need-help-with-natting/m-p/71973#M2814</link>
    <description>&lt;P&gt;so it turns out that there was a problem with the router configuration for the return traffic, upon asking the networking team about it i was told that there was no issues however upon doing a traceroute it was clear that there was a problem with the routing for the return traffic on a router, so eventually they did check it out properly and remade the routing for the router and everything is working fine now, thanks for replying anyways.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Jan 2020 17:58:08 GMT</pubDate>
    <dc:creator>kb1</dc:creator>
    <dc:date>2020-01-09T17:58:08Z</dc:date>
    <item>
      <title>this is very urgent, need help with natting</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/this-is-very-urgent-need-help-with-natting/m-p/71595#M2783</link>
      <description>&lt;P&gt;so im trying to nat traffic on my checkpoint 1100 appliance and unable to do so, no idea what mistake im making here, the ips that im using are 192.86.81.x,192.86.81.x,192.86.81.x and&amp;nbsp;192.86.81.x (4 of them), i was told that these ips should exist only on the firewall (so i created network host objects for each of these ips which im not sure of) , firewall has 2 interfaces lan5 and lan2 where the lan5 belongs to the unsecure network and the lan2 belongs to the secure network, so traffic flows into the lan5 interface from the gi0/1 interface of the router that it is connected to and is supposed (attaching a picture of a rough diagram of the network) to be natted to 10.169.x.x , 149.122.x.x,&amp;nbsp;149.122.x.x,&amp;nbsp;149.122.x.x respectively, now how do i accomplish this? i created an automatic rule for the 192.86.81.x ips where i specified the natted ips of 10.169.x.x , 149.122.x.x, etc accordingly (by double clicking the 192.86.x.x object i went into the nat part and chose static and specified the respective natted ips of 10.169.x.x , 149.122.x.x, etc) and then i published and installed the policy on the firewall, but when my co worker from the network team tries to ping say 192.86.81.x he does not receive any response, even when i try to ping these 192.86.81.x ips from the firewall itself i get no response, so what wrong am i doing here?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="diag.png" style="width: 960px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3922i7D76876A2E498F68/image-size/large?v=v2&amp;amp;px=999" role="button" title="diag.png" alt="diag.png" /&gt;&lt;/span&gt;&amp;nbsp; so as you can see in the diagram above traffic is supposed to flow in from the up arrow into the router then into gi0/1 and then into lan5 of the firewall which is where its supposed to get natted and then go out out lan2 into gi0/2 of the router and upwards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ive already configured routing and also configured the rules to allow any traffic flowing from gi0/1 into all the mentioned ips, so i know that its not because of some rule that is blocking the ping from gi0/1 of the router, since even i cannot ping the ips of 192.86.81.x from the firewall itself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the ips of 10.169.x.x, 149.122.x.x, etc are all pingable since these are alredy up and running.&lt;/P&gt;&lt;P&gt;So need help urgently!!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2020 22:20:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/this-is-very-urgent-need-help-with-natting/m-p/71595#M2783</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2020-01-03T22:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: this is very urgent, need help with natting</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/this-is-very-urgent-need-help-with-natting/m-p/71598#M2784</link>
      <description>If this is urgent you should involve the TAC.&lt;BR /&gt;The community does not have a specific SLA.&lt;BR /&gt;&lt;BR /&gt;Are there routes for the different 10 and 149 networks on the SMB gateway?&lt;BR /&gt;What does a tcpdump show when you're testing the NAT?&lt;BR /&gt;Also we need versions of management and gateway code.</description>
      <pubDate>Sat, 04 Jan 2020 02:24:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/this-is-very-urgent-need-help-with-natting/m-p/71598#M2784</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-01-04T02:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: this is very urgent, need help with natting</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/this-is-very-urgent-need-help-with-natting/m-p/71599#M2785</link>
      <description>To make sure the NAT is working you can type:&lt;BR /&gt;  fw ctl arp&lt;BR /&gt;Also be aware that on LAN ports you cannot create a default route.&lt;BR /&gt;Is the route on the router setup correctly?</description>
      <pubDate>Sat, 04 Jan 2020 07:55:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/this-is-very-urgent-need-help-with-natting/m-p/71599#M2785</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-01-04T07:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: this is very urgent, need help with natting</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/this-is-very-urgent-need-help-with-natting/m-p/71973#M2814</link>
      <description>&lt;P&gt;so it turns out that there was a problem with the router configuration for the return traffic, upon asking the networking team about it i was told that there was no issues however upon doing a traceroute it was clear that there was a problem with the routing for the return traffic on a router, so eventually they did check it out properly and remade the routing for the router and everything is working fine now, thanks for replying anyways.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 17:58:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/this-is-very-urgent-need-help-with-natting/m-p/71973#M2814</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2020-01-09T17:58:08Z</dc:date>
    </item>
  </channel>
</rss>

