<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hairpin NAT not working on 1490 with R77.20.70 in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14715#M377</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What was the fw monitor syntax you used to generate the above output?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Nov 2017 06:51:55 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2017-11-28T06:51:55Z</dc:date>
    <item>
      <title>Hairpin NAT not working on 1490 with R77.20.70</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14714#M376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need to configure a hairpin NAT on my gateway to allow Sonos connect to the internal Plex server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have defined a server in the Firewall -&amp;gt; Servers section and configured it with the option "Force translated traffic to return to the gateway", which stated "Allows access from internal networks to the external IP address of the server via local switch".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When sending traffic I can see that the gateway is allowing the traffic to pass, but it sends a reset back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;[vs_0][fw_2] LAN1:i[64]: 172.31.13.79 -&amp;gt; 178.84.193.195 (TCP) len=64 id=0&lt;BR /&gt;TCP: 62339 -&amp;gt; 56789 .S.... seq=5b68c0d2 ack=00000000&lt;BR /&gt;[vs_0][fw_2] LAN1:I[64]: 172.31.13.79 -&amp;gt; 178.84.193.195 (TCP) len=64 id=0&lt;BR /&gt;TCP: 62339 -&amp;gt; 56789 .S.... seq=5b68c0d2 ack=00000000&lt;BR /&gt;[vs_0][fw_2] LAN1:i[64]: 172.31.13.79 -&amp;gt; 178.84.193.195 (TCP) len=64 id=0&lt;BR /&gt;TCP: 62340 -&amp;gt; 56789 .S.... seq=1fbd82fb ack=00000000&lt;BR /&gt;[vs_0][fw_2] LAN1:I[64]: 172.31.13.79 -&amp;gt; 178.84.193.195 (TCP) len=64 id=0&lt;BR /&gt;TCP: 62340 -&amp;gt; 56789 .S.... seq=1fbd82fb ack=00000000&lt;BR /&gt;[vs_0][fw_2] LAN1:o[40]: 178.84.193.195 -&amp;gt; 172.31.13.79 (TCP) len=40 id=14750&lt;BR /&gt;TCP: 56789 -&amp;gt; 62339 ..R.A. seq=00000000 ack=5b68c0d3&lt;BR /&gt;[vs_0][fw_2] LAN1:O[40]: 178.84.193.195 -&amp;gt; 172.31.13.79 (TCP) len=40 id=14750&lt;BR /&gt;TCP: 56789 -&amp;gt; 62339 ..R.A. seq=00000000 ack=5b68c0d3&lt;BR /&gt;[vs_0][fw_2] LAN1:o[40]: 178.84.193.195 -&amp;gt; 172.31.13.79 (TCP) len=40 id=14751&lt;BR /&gt;TCP: 56789 -&amp;gt; 62340 ..R.A. seq=00000000 ack=1fbd82fc&lt;BR /&gt;[vs_0][fw_2] LAN1:O[40]: 178.84.193.195 -&amp;gt; 172.31.13.79 (TCP) len=40 id=14751&lt;BR /&gt;TCP: 56789 -&amp;gt; 62340 ..R.A. seq=00000000 ack=1fbd82fc&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;The logging shows that all translated info is zero. (see attachment)&lt;/P&gt;&lt;P&gt;How can I get this to work?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2017 05:59:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14714#M376</guid>
      <dc:creator>Robin_Gruyters</dc:creator>
      <dc:date>2017-11-28T05:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Hairpin NAT not working on 1490 with R77.20.70</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14715#M377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What was the fw monitor syntax you used to generate the above output?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2017 06:51:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14715#M377</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-11-28T06:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Hairpin NAT not working on 1490 with R77.20.70</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14716#M378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;```&lt;BR /&gt;fw monitor -e 'host(178.84.193.195), accept;'&lt;/P&gt;&lt;P&gt;```&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2017 08:32:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14716#M378</guid>
      <dc:creator>Robin_Gruyters</dc:creator>
      <dc:date>2017-11-28T08:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: Hairpin NAT not working on 1490 with R77.20.70</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14717#M379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have also checked with `fw ctl zdebug + drop` if traffic is blocked by the firewall, but nothing came up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2017 09:29:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14717#M379</guid>
      <dc:creator>Robin_Gruyters</dc:creator>
      <dc:date>2017-11-28T09:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: Hairpin NAT not working on 1490 with R77.20.70</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14718#M380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why is there only traffic on LAN1? What other interface is in use where the connection should leave the firewall?&lt;/P&gt;&lt;P&gt;If NAT is applied make sure you don't filter on the NATtes addresses.&lt;/P&gt;&lt;P&gt;You might be missing ICMP traffic here that might tell you what is going on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2017 11:55:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14718#M380</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-11-28T11:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Hairpin NAT not working on 1490 with R77.20.70</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14719#M381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Because other traffic isn't showing. (cut out)&lt;/P&gt;&lt;P&gt;At the moment of testing no other traffic (as much) is showing. (some DNS, but as much further. no ICMP redirects if you are wondering)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The client (172.31.13.79) needs to connect to the external (WAN) IP, 178.84.193.195, by using a hairpin NAT. The "Force translated traffic to return to the gateway" option on the 1490 indicates that is allowing this, but somehow it doesn't work on my gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check Point has a SK available for this purpose: &lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110019&amp;amp;partition=General&amp;amp;product=Security" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110019&amp;amp;partition=General&amp;amp;product=Security"&gt;How to configure NAT Loopback (Hairpin NAT / NAT Reflection) on Check Point Security Gateway&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2017 18:45:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14719#M381</guid>
      <dc:creator>Robin_Gruyters</dc:creator>
      <dc:date>2017-11-28T18:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Hairpin NAT not working on 1490 with R77.20.70</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14720#M382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;The option "Force translated traffic to return to the gateway" might be causing the server to reject the connection for some reason.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the 1490 the default gateway&amp;nbsp;of this server? If it is, then try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Uncheck&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;"Force translated traffic to return to the gateway"&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Create the incoming NAT rule for the&amp;nbsp;required service&lt;/LI&gt;&lt;LI&gt;Create a return NAT rule src:Server - dst:any - service:&amp;lt;desired-service&amp;gt; - Xlatedsrc:&lt;PRE style="color: #333333; background-color: #ffffff; border: 0px; margin: 0px;"&gt;178.84.193.195 - Xlatedst: Original - Xlatedsvc:Original&lt;/PRE&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is all I do and it usually works well. However, this won't work for other hosts in the same network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Nov 2017 12:16:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14720#M382</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2017-11-29T12:16:18Z</dc:date>
    </item>
    <item>
      <title>Re: Hairpin NAT not working on 1490 with R77.20.70</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14721#M383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you throw in a drawing? That will help to focus on the right issues.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Nov 2017 16:03:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Hairpin-NAT-not-working-on-1490-with-R77-20-70/m-p/14721#M383</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-11-29T16:03:57Z</dc:date>
    </item>
  </channel>
</rss>

