<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create a remote SMB cluster behind 3rd party NAT with central mgmt behind another cluster in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-create-a-remote-SMB-cluster-behind-3rd-party-NAT-with/m-p/190753#M9399</link>
    <description>&lt;P&gt;Should be possible using NAT-T:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk32664" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk32664&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk177823" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk177823&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Aug 2023 14:52:44 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-08-28T14:52:44Z</dc:date>
    <item>
      <title>How to create a remote SMB cluster behind 3rd party NAT with central mgmt behind another cluster?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-create-a-remote-SMB-cluster-behind-3rd-party-NAT-with/m-p/190634#M9392</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I am looking for some guidance with creating a new Checkpoint cluster using 1530 SMB appliances.&lt;/P&gt;&lt;P&gt;I have an existing OpenServer cluster at our HQ site (R81.10) with a central SMS (also R81.10) and I need to deploy the 1530 cluster at a remote site across the Internet and centrally manage it. These new appliances are also R81.10.&lt;/P&gt;&lt;P&gt;The remote site is behind a 3rd party firewall/NAT&amp;nbsp; with a single public IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This new cluster will be establishing a VPN tunnel to the HQ site.&lt;/P&gt;&lt;P&gt;The SMS is behind the HQ firewall with its own NAT'd public IP.&lt;/P&gt;&lt;P&gt;What is the best practice with respect to interface and gateway/cluster object IPs? For the new cluster and member objects, would I use the single remote public IP for all, or would I use the actual assigned physical private IPs, even though they aren't routable from the SMS? Do I need to try and obtain 3 public IPs for the remote site instead of just the one that have given me now? I'm not sure if that will be possible.&lt;/P&gt;&lt;P&gt;We use SmartConsole etc to manage the environment, we don't use any Checkpoint cloud management.&lt;/P&gt;&lt;P&gt;Here's my attempt at a diagram of the environment:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Drawing1.jpg" style="width: 723px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22209iE549D4060C6B468F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Drawing1.jpg" alt="Drawing1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 18:34:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-create-a-remote-SMB-cluster-behind-3rd-party-NAT-with/m-p/190634#M9392</guid>
      <dc:creator>Chris_W23</dc:creator>
      <dc:date>2023-08-25T18:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a remote SMB cluster behind 3rd party NAT with central mgmt behind another cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-create-a-remote-SMB-cluster-behind-3rd-party-NAT-with/m-p/190715#M9394</link>
      <description>&lt;P&gt;Why the 3rd party FW ? This makes things rather complicated...&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 11:32:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-create-a-remote-SMB-cluster-behind-3rd-party-NAT-with/m-p/190715#M9394</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-08-28T11:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a remote SMB cluster behind 3rd party NAT with central mgmt behind another cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-create-a-remote-SMB-cluster-behind-3rd-party-NAT-with/m-p/190731#M9395</link>
      <description>&lt;P&gt;The remote site is a partner's network and their current design has us implementing our appliance behind their firewall.&lt;/P&gt;&lt;P&gt;Is it too complex to do it this way? I can see if it can be installed along side their firewall instead of behind but that definitely wasn't their first choice.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 13:24:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-create-a-remote-SMB-cluster-behind-3rd-party-NAT-with/m-p/190731#M9395</guid>
      <dc:creator>Chris_W23</dc:creator>
      <dc:date>2023-08-28T13:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a remote SMB cluster behind 3rd party NAT with central mgmt behind another cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-create-a-remote-SMB-cluster-behind-3rd-party-NAT-with/m-p/190739#M9396</link>
      <description>&lt;P&gt;It is more complex than a HA Cluster facing internet. Why not do the VPN between 3rd party FW and HQ firewall ? Using a HA Cluster for VPN behind a single FW does not make much sense in regards to security for me...&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 13:56:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-create-a-remote-SMB-cluster-behind-3rd-party-NAT-with/m-p/190739#M9396</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-08-28T13:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a remote SMB cluster behind 3rd party NAT with central mgmt behind another cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-create-a-remote-SMB-cluster-behind-3rd-party-NAT-with/m-p/190743#M9397</link>
      <description>&lt;P&gt;Our corporate policies and requirements won't allow it.&lt;/P&gt;&lt;P&gt;I might just have to arrange for a separate ISP connection into that site and use it instead. Might be the best idea.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 14:01:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-create-a-remote-SMB-cluster-behind-3rd-party-NAT-with/m-p/190743#M9397</guid>
      <dc:creator>Chris_W23</dc:creator>
      <dc:date>2023-08-28T14:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to create a remote SMB cluster behind 3rd party NAT with central mgmt behind another cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-create-a-remote-SMB-cluster-behind-3rd-party-NAT-with/m-p/190753#M9399</link>
      <description>&lt;P&gt;Should be possible using NAT-T:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk32664" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk32664&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk177823" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk177823&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 14:52:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-to-create-a-remote-SMB-cluster-behind-3rd-party-NAT-with/m-p/190753#M9399</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-08-28T14:52:44Z</dc:date>
    </item>
  </channel>
</rss>

