<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Definition of remote Gateway behind NAT in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/22997#M940</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My environment is like the SK 101469 but the 1430 is Centrally Managed...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Jan 2019 09:20:29 GMT</pubDate>
    <dc:creator>Luigi_Vezzoso1</dc:creator>
    <dc:date>2019-01-10T09:20:29Z</dc:date>
    <item>
      <title>Definition of remote Gateway behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/22994#M937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;do you know how centrally managed the CP1430 behind a NAT router?&amp;nbsp; I have nat-ed all the required ports from the Router Public IP to the Firewall. We have some isue on the VPN establishing (invalid ID Identifier).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How I should configure the gateway on the SMS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;172.16.0.1/24 -&amp;gt; CheckpointGateway -&amp;gt; 192.168.1.1/24 -&amp;gt; Router -&amp;gt;PublicIP ---&amp;gt; CheckPointGateway ---&amp;gt; SMS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope is clear.... I can establish a SIC and push policy correcly. I also receve the log on the SMS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luigi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2019 17:04:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/22994#M937</guid>
      <dc:creator>Luigi_Vezzoso1</dc:creator>
      <dc:date>2019-01-09T17:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: Definition of remote Gateway behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/22995#M938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The gateway object IP on the SMS would be the public IP.&lt;/P&gt;&lt;P&gt;You said you configured NAT for the required ports--which ones specifically?&lt;/P&gt;&lt;P&gt;Also, when you try to either push policy, fetch policy, etc, what specific behavior do you see?&lt;/P&gt;&lt;P&gt;Error messages? Screen shots? Other information?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2019 21:44:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/22995#M938</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-09T21:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Definition of remote Gateway behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/22996#M939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have SIC and policy installs, you probably&amp;nbsp;got it right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VPN might require some further configuration to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT might be causing divergence between the IP address the CP1400 knows and what the peer knows. Check&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101469"&gt;sk101469&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk36425&amp;amp;partition=General&amp;amp;product=IPSec"&gt;sk36425 &lt;/A&gt;explains a similar issue, but caused by ISP redundancy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 03:23:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/22996#M939</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2019-01-10T03:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Definition of remote Gateway behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/22997#M940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My environment is like the SK 101469 but the 1430 is Centrally Managed...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 09:20:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/22997#M940</guid>
      <dc:creator>Luigi_Vezzoso1</dc:creator>
      <dc:date>2019-01-10T09:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Definition of remote Gateway behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/22998#M941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume you want a VPN to 3rd party VPN as explained here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec"&gt;sk108600: &lt;STRONG&gt;VPN&lt;/STRONG&gt; Site-to-Site with 3rd party&lt;/A&gt;&amp;nbsp;- maybe you should set the&amp;nbsp;ID Type not to IP address but something else...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 11:23:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/22998#M941</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-01-10T11:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: Definition of remote Gateway behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/22999#M942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nope, the both side are checkpoint gateways centrally managed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 11:25:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/22999#M942</guid>
      <dc:creator>Luigi_Vezzoso1</dc:creator>
      <dc:date>2019-01-10T11:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Definition of remote Gateway behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/23000#M943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please read&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600&amp;amp;partition=Advanced&amp;amp;product=IPSec" rel="nofollow" style="color: #e45785; background-color: #ffffff; border: 0px; text-decoration: underline; padding: 0px calc(12px + 0.35ex) 0px 0px;"&gt;sk108600&lt;/A&gt;&amp;nbsp;-&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;maybe you should set the&amp;nbsp;ID Type not to IP address but something else as i think it does send a wrong IP address... But you can analyze that using VPN Debug!&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Jan 2019 11:30:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/23000#M943</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-01-10T11:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Definition of remote Gateway behind NAT</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/162920#M7820</link>
      <description>&lt;P&gt;I have a similar setup but it fails on the SIC allready. In the SIC I see the LAN side IP adres in reverse notation and the match can't be made.&lt;/P&gt;
&lt;P&gt;The hostname equals the object name in the policy for the Central firewall.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;(SecurityPeer sent wrong DN: 1.255.168.192** Reset SIC from peer, and establish trust again. **)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 12:17:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Definition-of-remote-Gateway-behind-NAT/m-p/162920#M7820</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2022-11-23T12:17:53Z</dc:date>
    </item>
  </channel>
</rss>

