<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: problem with monitoring 1500 appliance LTE in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143101#M6536</link>
    <description>&lt;P&gt;Please explain the NAT used here - sounds like &amp;nbsp;static NAT, not dynamic IP to me...&lt;/P&gt;</description>
    <pubDate>Mon, 07 Mar 2022 08:06:24 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2022-03-07T08:06:24Z</dc:date>
    <item>
      <title>problem with monitoring 1500 appliance LTE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143069#M6530</link>
      <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;
&lt;P&gt;we had a bunch of 1500 appliances connected to the internet via LTE. Everything is working fine, VPN tunnels are up and traffic flows. But all appliances are shown as disconnected in Smartconsole/SmartviewMonitor. After debug we could see the LTE provider did some NAT for the appliance. The Managementserver does not get the real IP of the appliance, only the NATed IP. I think this is normal behaviour if any NAT is done on the way between remote and central gateway but do we have any chance to get a green state in Smartconsole for the LTE appliances with dynamic IPs?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Mar 2022 17:22:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143069#M6530</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-03-06T17:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: problem with monitoring 1500 appliance LTE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143082#M6531</link>
      <description>&lt;P&gt;Review the following articles&amp;nbsp;&lt;SPAN&gt;sk120136 / sk93566 as a start, not all implied rules apply for traffic from DAIP gateways ...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 00:53:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143082#M6531</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-03-07T00:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: problem with monitoring 1500 appliance LTE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143092#M6534</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&amp;nbsp;checked these sarticles, everything looks fine. SmartProvisioning is mentioned in the article but we don't use this feature, alle gateways are defined as normal DAIP gateways. There are no firewall-rules between remote and central gateway.&lt;/P&gt;
&lt;P&gt;Can you please explain the needed traffic flow for the "connect" state. Will be there a need for a cpd_amon connection from the management to the remote DAIP gateway or vice versa?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 07:16:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143092#M6534</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-03-07T07:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: problem with monitoring 1500 appliance LTE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143101#M6536</link>
      <description>&lt;P&gt;Please explain the NAT used here - sounds like &amp;nbsp;static NAT, not dynamic IP to me...&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 08:06:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143101#M6536</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-07T08:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: problem with monitoring 1500 appliance LTE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143102#M6537</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;we have no information which kind of NAT is done via the LTE provider, this is something&amp;nbsp;mysterious done by the&amp;nbsp; German Telekom in the LTE network. We could see the appliance getting IP-adress (10.xx.xx.xx) but on the management we could see the appliance as 80.xx.xx.xx.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 08:34:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143102#M6537</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-03-07T08:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: problem with monitoring 1500 appliance LTE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143105#M6538</link>
      <description>&lt;P&gt;Central gateway has rules in-place of the implied rules for the traffic from DAIP gateway/s or is mgmt traffic via VPN?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 08:45:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143105#M6538</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-03-07T08:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: problem with monitoring 1500 appliance LTE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143108#M6539</link>
      <description>&lt;P&gt;Then maybe you can just be glad that VPN is working&amp;nbsp;8)&lt;/img&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 09:32:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143108#M6539</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-07T09:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: problem with monitoring 1500 appliance LTE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143114#M6540</link>
      <description>&lt;P&gt;Yes, rules exists for the management ports like cpd, fw_log, cpd_amon etc.&amp;nbsp; VPN is working fine, logs are sent to the management. Only the state of the appliance is not shown as connected and the state of the VPN tunnel is shown as down in SmartviewMonitor.&lt;/P&gt;
&lt;P&gt;Are there any requirements if the appliance will be installed behind another NAT-device ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 09:54:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143114#M6540</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-03-07T09:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: problem with monitoring 1500 appliance LTE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143377#M6548</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;my question again.... we had a DAIP appliance behind a NAT device, only NAT no firewall. Will it be possible to get these appliance to the green state meaning "connected" in Smartconsole view ?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 16:24:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143377#M6548</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-03-09T16:24:49Z</dc:date>
    </item>
    <item>
      <title>Re: problem with monitoring 1500 appliance LTE</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143398#M6550</link>
      <description>&lt;P&gt;I've sought some feedback on your behalf (in the absence of a corresponding SK etc) and will update you accordingly.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2022 07:05:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/problem-with-monitoring-1500-appliance-LTE/m-p/143398#M6550</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-03-10T07:05:36Z</dc:date>
    </item>
  </channel>
</rss>

