<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No internet with NAT and internal routing problem in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/No-internet-with-NAT-and-internal-routing-problem/m-p/118393#M5197</link>
    <description>&lt;P&gt;The routing problem is resolved. It was a problem with the network adapter of network2. Changed to another adapter and everything ist fine.&lt;/P&gt;&lt;P&gt;What I still don't quite understand is the behavior of the NAT settings. As long as the switch for outgoing traffic is set to ON under "Access Policy -&amp;gt; NAT", requests go out, but no responses come back.&lt;BR /&gt;Unfortunately, the only option that helps is to define your own NAT rules: Translate traffic from network1 to any destination on any service, as if the traffic is hidden behind gateway_ip to original destination on original service.&lt;BR /&gt;And the same with the other networks.&lt;/P&gt;&lt;P&gt;It works, but it didn't feel right.&lt;/P&gt;</description>
    <pubDate>Fri, 14 May 2021 13:58:21 GMT</pubDate>
    <dc:creator>MatWre</dc:creator>
    <dc:date>2021-05-14T13:58:21Z</dc:date>
    <item>
      <title>No internet with NAT and internal routing problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/No-internet-with-NAT-and-internal-routing-problem/m-p/118290#M5183</link>
      <description>&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/45104"&gt;@All&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;we've installed a FW 1530 with R80.20.25. The problem seems to be near to &lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-10-NAT-issue/td-p/27687" target="_self"&gt;R80.10 NAT issue&lt;/A&gt; but it's not the same.&lt;/P&gt;&lt;P&gt;We defind a switch for LAN1-4 with local network 192.168.0.0/24 (network1) and the subnet 192.168.1.0/24 (network2) on LAN5.&lt;/P&gt;&lt;P&gt;We've a static IP un WAN and the connection works fine. Updates are loaded and Ping/Traceroute from web-gui are working correct. We did'nt define manual policies.&lt;/P&gt;&lt;P&gt;The problem is, that the clients won't connect to internet, as long as NAT is enabled. The connections only works, while NAT for outgoing traffic is disabled with manual NAT rules.&lt;BR /&gt;- &amp;lt;network1&amp;gt;, any, any, &amp;lt;wan ip (hide)&amp;gt;, original, original&lt;BR /&gt;- &amp;lt;network2&amp;gt;, any, any, &amp;lt;wan ip (hide)&amp;gt;, original, original&lt;/P&gt;&lt;P&gt;From this moment on, both networks are working, but the problem is, that we're not able to connect from one internal network to another.&lt;/P&gt;&lt;P&gt;When I heve a look at the routing table, everything seems to be fine:&lt;BR /&gt;1. &amp;lt;network1&amp;gt;, any, any, LAN1, 0, directly attached&lt;BR /&gt;2. &amp;lt;network2&amp;gt;, any, any, LAN5, 0, directly attached&lt;BR /&gt;3. &amp;lt;wan subnet&amp;gt;, any, any, WAN, 0, directly attached&lt;BR /&gt;4. Default, any, any, &amp;lt;wan gateway&amp;gt;, 0, default ...&lt;/P&gt;&lt;P&gt;The routing table from the command output is showing the result in reverse order. It's confusing.&lt;/P&gt;&lt;P&gt;All traceroutes from &amp;lt;network1&amp;gt; to &amp;lt;network2&amp;gt; are routing directly to wan and the connection fails.&lt;/P&gt;&lt;P&gt;Thanks for your ideas.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 12 May 2021 18:58:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/No-internet-with-NAT-and-internal-routing-problem/m-p/118290#M5183</guid>
      <dc:creator>MatWre</dc:creator>
      <dc:date>2021-05-12T18:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: No internet with NAT and internal routing problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/No-internet-with-NAT-and-internal-routing-problem/m-p/118301#M5184</link>
      <description>&lt;P&gt;But those rules don’t look like NAT is disabled but rather configured with a manual NAT rule?&lt;BR /&gt;Also, so you have an explicit rule permitting the two networks to talk to one another?&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2021 01:45:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/No-internet-with-NAT-and-internal-routing-problem/m-p/118301#M5184</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-13T01:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: No internet with NAT and internal routing problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/No-internet-with-NAT-and-internal-routing-problem/m-p/118393#M5197</link>
      <description>&lt;P&gt;The routing problem is resolved. It was a problem with the network adapter of network2. Changed to another adapter and everything ist fine.&lt;/P&gt;&lt;P&gt;What I still don't quite understand is the behavior of the NAT settings. As long as the switch for outgoing traffic is set to ON under "Access Policy -&amp;gt; NAT", requests go out, but no responses come back.&lt;BR /&gt;Unfortunately, the only option that helps is to define your own NAT rules: Translate traffic from network1 to any destination on any service, as if the traffic is hidden behind gateway_ip to original destination on original service.&lt;BR /&gt;And the same with the other networks.&lt;/P&gt;&lt;P&gt;It works, but it didn't feel right.&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 13:58:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/No-internet-with-NAT-and-internal-routing-problem/m-p/118393#M5197</guid>
      <dc:creator>MatWre</dc:creator>
      <dc:date>2021-05-14T13:58:21Z</dc:date>
    </item>
    <item>
      <title>Re: No internet with NAT and internal routing problem</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/No-internet-with-NAT-and-internal-routing-problem/m-p/118394#M5198</link>
      <description>&lt;P&gt;Thanks for your reply. Routing was a problem of the NIC of network2. With another NIC this problem ist solved.&lt;/P&gt;&lt;P&gt;I have described the NAT behavior again in a direct reply to my post.&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 14:04:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/No-internet-with-NAT-and-internal-routing-problem/m-p/118394#M5198</guid>
      <dc:creator>MatWre</dc:creator>
      <dc:date>2021-05-14T14:04:44Z</dc:date>
    </item>
  </channel>
</rss>

