<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT rules for DMZ object in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140445#M6308</link>
    <description>&lt;P&gt;All good brother...glad it's fixed!&lt;/P&gt;</description>
    <pubDate>Thu, 03 Feb 2022 23:56:40 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-02-03T23:56:40Z</dc:date>
    <item>
      <title>NAT rules for DMZ object</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140314#M6301</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whilst deploying&amp;nbsp; pair of Checkpoint 1590 Appliances running R80.20&amp;nbsp; I noticed some strange behaviour which I have been unable to resolve&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am succesfully able to NAt source IPs for remote VPN sources for inbound traffic passing through to internal networks, as well as internal objects destined for remote IPSEC VPN networks but am struggling to NAT a network object defined in the DMZ leg heading inbound to internal networks. Something which I was able to do with R71 without any issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;DMZ 192.168.230.x&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LAN7 172.17.x.x&lt;/P&gt;&lt;P&gt;----------------------- CHECKPOINT 1590 --------------------JUNIPER---- Router----172.22.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So basically I'd like to NAT an object with has an IP of 192.168.230.20 to SNAT 192.168.230.10 when communicating hosts in 172.22&lt;/P&gt;&lt;P&gt;SO I have a manual NAT rule which does exactly that for 172.22.x.x destination . However, what ever I do , the traffic is not NATed if I tcpdump the LAN7 interface. I still see the traffic leave as 192.168.230.20 and not 192.168.230.10.&lt;/P&gt;&lt;P&gt;Additionally if I try to either hide behind the internet interface for outbound traffic with the option to SNAT behind internet Gateway or set a manual NAT for internet access, again this object's source IP is not NAT'ed. SO I was wondering are there any implicit rules or functions that treat traffic on the inbuilt predefined DMZ interface differently perhaps?&lt;/P&gt;&lt;P&gt;I have successfully managed to configure traffic from the internal 172.22.x.x to SNAT behind an IP on the LAN7 range en route to a remote host VPN ...&lt;/P&gt;&lt;P&gt;Is there something simple here that I am missing, are objects in the DMZ managed differently?&lt;/P&gt;&lt;P&gt;For completeness, I will try moving the 192.168.230.0/24 network to a normal LAN port when in the office again tomorrow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for your assistance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Dek&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 02 Feb 2022 23:50:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140314#M6301</guid>
      <dc:creator>DekPlent</dc:creator>
      <dc:date>2022-02-02T23:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rules for DMZ object</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140317#M6302</link>
      <description>&lt;P&gt;Is this R80.20.35 build 2577 or other version and is it centrally managed?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 01:20:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140317#M6302</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-03T01:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rules for DMZ object</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140327#M6303</link>
      <description>&lt;P&gt;From my knowledge, I don't believe nat rules for DMZ would be any different. If this is centrally managed appliance, you would do it same way in dashboard as before, however, if it is locally managed, its possible it would be a bit different, so you may want to confirm that with TAC smb team. Just curious though, if it is locally managed, what does nat rule you created look like...can you paste the screenshot here?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 01:27:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140327#M6303</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-03T01:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rules for DMZ object</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140350#M6304</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;It is locally managed and is build 2467. There is a story there too.. One of the two appliances wanted to go to 2577 and the other one would only&amp;nbsp; see 2467 as the latest build when checking for updates. At the time also, I could only download 2467 as the latest build and so I could not manually upgrade the unit to 2577.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 08:53:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140350#M6304</guid>
      <dc:creator>DekPlent</dc:creator>
      <dc:date>2022-02-03T08:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rules for DMZ object</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140420#M6305</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;I got into the office to find that there was a power outage at the site... Both 1590s are up and NOW the natting is working and there has been no change, which is highly unsatisfactory not knowing why it is now working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I may add another host to see what happens when trying to SNAT again. Thanks for your time and Chris, sorry I have not been able to provide any more insight.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dek&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 17:42:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140420#M6305</guid>
      <dc:creator>DekPlent</dc:creator>
      <dc:date>2022-02-03T17:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rules for DMZ object</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140442#M6306</link>
      <description>&lt;P&gt;Hi Chris, I may try build 2577. Are you using this currently?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 23:18:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140442#M6306</guid>
      <dc:creator>DekPlent</dc:creator>
      <dc:date>2022-02-03T23:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: NAT rules for DMZ object</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140445#M6308</link>
      <description>&lt;P&gt;All good brother...glad it's fixed!&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 23:56:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/NAT-rules-for-DMZ-object/m-p/140445#M6308</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-03T23:56:40Z</dc:date>
    </item>
  </channel>
</rss>

