<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN route over WAN link in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193103#M9522</link>
    <description>&lt;P&gt;Good afternoon,&lt;/P&gt;&lt;P&gt;I tried to draw a picture here, I'm terrible, I hope you can understand. haha ha&lt;/P&gt;&lt;P&gt;How would I do Nat? I tried and was unsuccessful, could you please tell me?&lt;/P&gt;&lt;P&gt;I need the communication from the equipment at site 2 to arrive at site 1 with its LAN IP, in the server logs and via tracert, it reports that it arrived with the WAN IP.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Sep 2023 19:55:44 GMT</pubDate>
    <dc:creator>Mayron</dc:creator>
    <dc:date>2023-09-19T19:55:44Z</dc:date>
    <item>
      <title>VPN route over WAN link</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193089#M9520</link>
      <description>&lt;P&gt;Good afternoon,&lt;/P&gt;&lt;P&gt;I have 2 SMBs added from Checkpoint Management, I closed the VPN using SIC and VPN COMUTIES, when I try to access or ping the servers at both ends, it responds normally.&lt;/P&gt;&lt;P&gt;However, when I give a TRACERT on the LAN IP, it should go out through the firewall's LAN IP to the head office and vice versa, but it is going out to the public IP (WAN) and then arrives on the LAN network on the other side.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EXAMPLE:&lt;/P&gt;&lt;P&gt;tracert 192.168.0.100&lt;/P&gt;&lt;P&gt;1&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;lt;1 ms &amp;lt;1 ms &amp;lt;1 ms 192.168.200.247 - IP FW MATRIZ (FICTICIO)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2&amp;nbsp; &amp;nbsp; &amp;nbsp; 5 ms 7 ms 7 ms 186.201.133.84 - WAN IP OF THE UNIT&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;3&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8 ms 7 ms 6 ms 192.168.0.100 UNIT LAN IP&lt;/P&gt;&lt;P&gt;This is causing me a problem, I have equipment in the unit that needs to communicate with a server in the head office, but it has to be with the LAN IP, it is arriving with the WAN IP, and the connection is not completed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone experienced a similar problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance for your support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 18:11:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193089#M9520</guid>
      <dc:creator>Mayron</dc:creator>
      <dc:date>2023-09-19T18:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN route over WAN link</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193099#M9521</link>
      <description>&lt;P&gt;A simple network diagram will go a long way to helping us resolve your issue.&lt;/P&gt;
&lt;P&gt;For traceroute in particular, what you're seeing is expected behavior.&lt;BR /&gt;Responses will always come from the nearest IP, even if you traceroute to a different IP on the same system.&lt;BR /&gt;From the remote end, the WAN IP is "nearest" to where the traceroute is coming from, therefore it will be used in all responses.&lt;/P&gt;
&lt;P&gt;You will most likely need to configure a manual NAT rule here.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 19:32:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193099#M9521</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-19T19:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN route over WAN link</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193103#M9522</link>
      <description>&lt;P&gt;Good afternoon,&lt;/P&gt;&lt;P&gt;I tried to draw a picture here, I'm terrible, I hope you can understand. haha ha&lt;/P&gt;&lt;P&gt;How would I do Nat? I tried and was unsuccessful, could you please tell me?&lt;/P&gt;&lt;P&gt;I need the communication from the equipment at site 2 to arrive at site 1 with its LAN IP, in the server logs and via tracert, it reports that it arrived with the WAN IP.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 19:55:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193103#M9522</guid>
      <dc:creator>Mayron</dc:creator>
      <dc:date>2023-09-19T19:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN route over WAN link</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193108#M9523</link>
      <description>&lt;P&gt;The diagram is fine except it's not clear what side of the diagram is initiating the connection.&lt;BR /&gt;A NAT rule will not resolve the issue with traceroute this since the traffic is originating from the gateway itself.&lt;BR /&gt;It's also expected behavior.&lt;/P&gt;
&lt;P&gt;You said you tried to do NAT.&lt;BR /&gt;Please show exactly what you attempted to do (with screenshots).&lt;BR /&gt;When you defined the site, did you disable the NAT option shown here?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22509i9B9AA0D063DA0B6B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Ensuring this is disabled should cause the traffic to not be subject to NAT at all (i.e. come from a 192.168.0.x address).&lt;BR /&gt;If it has to come from the LAN IP of the gateway (and not it's original LAN IP), then this option will need to be enabled and a manual NAT rule will need to be created.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 20:12:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193108#M9523</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-19T20:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN route over WAN link</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193112#M9524</link>
      <description>&lt;P&gt;Good afternoon, in this case I use it through centralized management, the configuration is done in the Smart Console, following the attached nat rule, which I had tested.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 20:39:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193112#M9524</guid>
      <dc:creator>Mayron</dc:creator>
      <dc:date>2023-09-19T20:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN route over WAN link</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193173#M9526</link>
      <description>&lt;P&gt;There is a similar setting in the VPN Community for centrally managed gateways:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22517i0D126199F0AE033E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If you enable this checkbox and push policy to the relevant gateways, a NAT rule should not be necessary.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 16:37:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193173#M9526</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-20T16:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN route over WAN link</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193178#M9527</link>
      <description>&lt;P&gt;Good afternoon,&lt;/P&gt;&lt;P&gt;Perfect, I understand, we are on the right track, I enabled it and it stopped appearing in my server's log which is coming through the unit's WAN IP, but I still haven't shown the IP of the equipment but rather the firewall of my Headquarters, inserting a printout below.&lt;/P&gt;&lt;P&gt;It should not arrive with &lt;STRONG&gt;IP 192.168.0.247&lt;/STRONG&gt; which is from the matrix firewall, it should arrive with &lt;STRONG&gt;IP 192.168.200.100&lt;/STRONG&gt; which would be the LAN IP of the equipment in the unit.&lt;/P&gt;&lt;P&gt;I am attaching the complete Community configuration.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture 5.jpg" style="width: 763px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22519iDB19622DC9C606CF/image-dimensions/763x555?v=v2" width="763" height="555" role="button" title="Capture 5.jpg" alt="Capture 5.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Server Log.jpg" style="width: 800px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22520iE805E4D240C9FA75/image-dimensions/800x188?v=v2" width="800" height="188" role="button" title="Server Log.jpg" alt="Server Log.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 17:31:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193178#M9527</guid>
      <dc:creator>Mayron</dc:creator>
      <dc:date>2023-09-20T17:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN route over WAN link</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193295#M9531</link>
      <description>&lt;P&gt;Hello partner, I still have the same problem, testing it but I couldn't get it to arrive correctly, any ideas so I can test it?&lt;/P&gt;&lt;P&gt;I appreciate all the support.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 22:23:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193295#M9531</guid>
      <dc:creator>Mayron</dc:creator>
      <dc:date>2023-09-21T22:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: VPN route over WAN link</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193390#M9534</link>
      <description>&lt;P&gt;I'm not clear what the "matrix" firewall is, or, really where anything in the diagram is.&lt;BR /&gt;Please reattach a diagram making the following items clearly noted:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Where traffic is originating from&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Where your Quantum Spark device is (the one we're talking about the configuration of)&lt;/LI&gt;
&lt;LI&gt;Where your "headquarters" firewall is&lt;/LI&gt;
&lt;LI&gt;Where the traffic is ultimately destined for&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In any case, if the traffic is leaving the SMB gateway with the correct IP according to the logs, then the NAT probably isn't happening at the SMB gateway.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 22:43:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/VPN-route-over-WAN-link/m-p/193390#M9534</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-22T22:43:54Z</dc:date>
    </item>
  </channel>
</rss>

