<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN S2S CP 700 Series WAN Behind NAT in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143740#M6584</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Is it possible to configure what ip address Checkpoint 730 should present itself when connecting VPN S2S? It's about the WAN address.&lt;/P&gt;&lt;P&gt;Currently, the WAN port of Checkpoint 730 has a local 1: 1 nat address from a public IP.&lt;/P&gt;&lt;P&gt;All ports and services are not blocked by the provider. The problem is only the local IP address on the WAN nat 1: 1 port from the public address.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Mar 2022 12:14:20 GMT</pubDate>
    <dc:creator>luk89as</dc:creator>
    <dc:date>2022-03-15T12:14:20Z</dc:date>
    <item>
      <title>VPN S2S CP 700 Series WAN Behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143463#M6554</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have two Chececkpoint 750 and 730 gates.&lt;/P&gt;&lt;P&gt;Checkpoint 750 has an assigned public IP address on the WAN port.&lt;/P&gt;&lt;P&gt;Checkpint 730 is assigned a local IP address on the WAN port.&lt;/P&gt;&lt;P&gt;The address on the Checkpoint 730's WAN port is NAT 1: 1 from a public IP address.&lt;/P&gt;&lt;P&gt;This configuration results from the change of the link provider.&lt;/P&gt;&lt;P&gt;In the old configuration where both Checkpoints had public addresses on WAN ports, the S2S VPN connection worked without any problems.&lt;/P&gt;&lt;P&gt;After changing link provider and NAT public address to local WAN 1: 1 address, Checkpoint 730 presents itself to local WAN address. For this reason, the S2S VPN does not work.&lt;/P&gt;&lt;P&gt;In the S2S Checkpoint 750 VPN configuration, I configured the remote site behind NAT and provided the local address it was behind.&lt;/P&gt;&lt;P&gt;Still, it doesn't work.&lt;/P&gt;&lt;P&gt;Am I making a configuration error or is the supplier blocking something? Normal Gate &amp;lt;--&amp;gt; client connection works fine.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 07:20:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143463#M6554</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2022-03-11T07:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S CP 700 Series WAN Behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143471#M6555</link>
      <description>&lt;P&gt;Can we move this post to Spark/SMB, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 08:11:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143471#M6555</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-11T08:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S CP 700 Series WAN Behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143475#M6556</link>
      <description>&lt;P&gt;OK. Please&amp;nbsp;&lt;SPAN&gt;move this post to Spark/SMB&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 08:49:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143475#M6556</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2022-03-11T08:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S CP 700 Series WAN Behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143477#M6557</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;done. Also, you now are able to move the posts yourself &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Please use this with caution.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 08:57:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143477#M6557</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-03-11T08:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S CP 700 Series WAN Behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143480#M6558</link>
      <description>&lt;P&gt;I promise that i will&amp;nbsp;8)&lt;/img&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 09:12:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143480#M6558</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-11T09:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S CP 700 Series WAN Behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143740#M6584</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Is it possible to configure what ip address Checkpoint 730 should present itself when connecting VPN S2S? It's about the WAN address.&lt;/P&gt;&lt;P&gt;Currently, the WAN port of Checkpoint 730 has a local 1: 1 nat address from a public IP.&lt;/P&gt;&lt;P&gt;All ports and services are not blocked by the provider. The problem is only the local IP address on the WAN nat 1: 1 port from the public address.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 12:14:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143740#M6584</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2022-03-15T12:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S CP 700 Series WAN Behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143742#M6585</link>
      <description>&lt;P&gt;Can be configured in Advanced Settings:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AdvancedVPN.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15691iB73801C589AC7B7A/image-size/large?v=v2&amp;amp;px=999" role="button" title="AdvancedVPN.png" alt="AdvancedVPN.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If that is not what you try to achieve, look at the other VPN S2S settings&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 12:29:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/143742#M6585</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-15T12:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S CP 700 Series WAN Behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/160024#M7611</link>
      <description>&lt;P&gt;I started S2S VPN connection.&lt;/P&gt;&lt;P&gt;In the S2S VPN settings I checked the option: "Disable NAT for this site"&lt;/P&gt;&lt;P&gt;I applied the setting to both Checkpoint devices.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 06:24:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/160024#M7611</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2022-10-20T06:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S CP 700 Series WAN Behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/160206#M7621</link>
      <description>&lt;P&gt;Does the new ISP link use CG-NAT where public IP is shared with other subscribers?&lt;BR /&gt;If so, using aggressive mode from CP730 to CP750 might be a choice. (CP730 as initiator, CP750 as responder)&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 06:13:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-S2S-CP-700-Series-WAN-Behind-NAT/m-p/160206#M7621</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2022-10-24T06:13:35Z</dc:date>
    </item>
  </channel>
</rss>

