<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB appliances not logging NAT on networks behind VLANs in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-not-logging-NAT-on-networks-behind-VLANs/m-p/94662#M4065</link>
    <description>&lt;P&gt;Sounds like we might need a TAC case after trying R80.20.10&lt;/P&gt;</description>
    <pubDate>Wed, 19 Aug 2020 23:01:21 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-08-19T23:01:21Z</dc:date>
    <item>
      <title>SMB appliances not logging NAT on networks behind VLANs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-not-logging-NAT-on-networks-behind-VLANs/m-p/94429#M4040</link>
      <description>&lt;P&gt;There is an inconsistency in logging traffic from Internal networks connected to the LAN# interfaces and LAN#.## VLANs of SMB appliances.&lt;/P&gt;
&lt;P&gt;On my 1550 R80.20.05 (992001208), with two networks defined, 10.x.x.x on LAN1 and 192.x.x.x on LAN2.10, Global NAT for Internal Networks enabled:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1550_Networks.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7685iB0F6BB593B17D3D2/image-size/large?v=v2&amp;amp;px=999" role="button" title="1550_Networks.png" alt="1550_Networks.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Global_NAT_Settings_for_Internal_Networks.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7688i8761472061B4E331/image-size/large?v=v2&amp;amp;px=999" role="button" title="Global_NAT_Settings_for_Internal_Networks.png" alt="Global_NAT_Settings_for_Internal_Networks.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1550_NAT_Logged_Properly.png" style="width: 921px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7686i2FD59C44F3D5D40A/image-size/large?v=v2&amp;amp;px=999" role="button" title="1550_NAT_Logged_Properly.png" alt="1550_NAT_Logged_Properly.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1550_NAT_NOT_Logged_Properly.png" style="width: 921px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7687iF8F5FC5F826B2943/image-size/large?v=v2&amp;amp;px=999" role="button" title="1550_NAT_NOT_Logged_Properly.png" alt="1550_NAT_NOT_Logged_Properly.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NAT is actually working fine, but the logs are all over the place:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Windows_Server_MYIP_Lookup.png" style="width: 634px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7689i06B19DF62590EDC0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Windows_Server_MYIP_Lookup.png" alt="Windows_Server_MYIP_Lookup.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, in the Security Logs List view, we can see the Interfaces:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1550_NAT_Logs.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7690i2B557124D842DC72/image-size/large?v=v2&amp;amp;px=999" role="button" title="1550_NAT_Logs.png" alt="1550_NAT_Logs.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But in Log Details, this data is absent.&lt;/P&gt;
&lt;P&gt;Additionally, there is no way that I see to define the Network as "Internal":&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1550_Network_Properies.png" style="width: 451px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7691i249E5E8DDDF33C7B/image-size/large?v=v2&amp;amp;px=999" role="button" title="1550_Network_Properies.png" alt="1550_Network_Properies.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 22:33:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-not-logging-NAT-on-networks-behind-VLANs/m-p/94429#M4040</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2020-08-17T22:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliances not logging NAT on networks behind VLANs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-not-logging-NAT-on-networks-behind-VLANs/m-p/94662#M4065</link>
      <description>&lt;P&gt;Sounds like we might need a TAC case after trying R80.20.10&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 23:01:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-not-logging-NAT-on-networks-behind-VLANs/m-p/94662#M4065</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-19T23:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: SMB appliances not logging NAT on networks behind VLANs</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-not-logging-NAT-on-networks-behind-VLANs/m-p/94664#M4066</link>
      <description>&lt;P&gt;If you are going to open an SR, please include the bit about missing interface data in the body of the events.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2020 23:04:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-appliances-not-logging-NAT-on-networks-behind-VLANs/m-p/94664#M4066</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2020-08-19T23:04:57Z</dc:date>
    </item>
  </channel>
</rss>

