<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CP1570 VPN S2S to Palo Alto - NAT translation in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CP1570-VPN-S2S-to-Palo-Alto-NAT-translation/m-p/199892#M9933</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have an S2S CP1570 and a Palo Alto connected via VPN.&lt;/P&gt;&lt;P&gt;The server behind Palo Alto is assigned the IP 172.28.148.1&lt;/P&gt;&lt;P&gt;The server (IP 172.28.148.1) behind Palo Alto will only respond to a PING query as traffic from the CP1570 side will come from the 172.29.148.0/24 network passing through the VPN tunnel.&lt;/P&gt;&lt;P&gt;How do I do a 1:1 NAT translation so that when I send a PING from the 192.168.88.0/24 network it will be sent through the VPN tunnel as an IP from the 172.29.148.0/24 network.&lt;/P&gt;&lt;P&gt;If this is not possible I will have to assign a static address from the 172.29.148.0/24 network to the computer's network card&lt;/P&gt;&lt;P&gt;I am attaching an image with a block diagram.&lt;/P&gt;&lt;P&gt;CP1570 Firmware&amp;nbsp; R81.10.08 (996001683)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Dec 2023 16:45:57 GMT</pubDate>
    <dc:creator>luk89as</dc:creator>
    <dc:date>2023-12-06T16:45:57Z</dc:date>
    <item>
      <title>CP1570 VPN S2S to Palo Alto - NAT translation</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CP1570-VPN-S2S-to-Palo-Alto-NAT-translation/m-p/199892#M9933</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have an S2S CP1570 and a Palo Alto connected via VPN.&lt;/P&gt;&lt;P&gt;The server behind Palo Alto is assigned the IP 172.28.148.1&lt;/P&gt;&lt;P&gt;The server (IP 172.28.148.1) behind Palo Alto will only respond to a PING query as traffic from the CP1570 side will come from the 172.29.148.0/24 network passing through the VPN tunnel.&lt;/P&gt;&lt;P&gt;How do I do a 1:1 NAT translation so that when I send a PING from the 192.168.88.0/24 network it will be sent through the VPN tunnel as an IP from the 172.29.148.0/24 network.&lt;/P&gt;&lt;P&gt;If this is not possible I will have to assign a static address from the 172.29.148.0/24 network to the computer's network card&lt;/P&gt;&lt;P&gt;I am attaching an image with a block diagram.&lt;/P&gt;&lt;P&gt;CP1570 Firmware&amp;nbsp; R81.10.08 (996001683)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 16:45:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CP1570-VPN-S2S-to-Palo-Alto-NAT-translation/m-p/199892#M9933</guid>
      <dc:creator>luk89as</dc:creator>
      <dc:date>2023-12-06T16:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: CP1570 VPN S2S to Palo Alto - NAT translation</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CP1570-VPN-S2S-to-Palo-Alto-NAT-translation/m-p/199911#M9934</link>
      <description>&lt;P&gt;I am not familiar with the model CP1570, but normally if using a domain/policy based VPN, you need to add the host/networks/ranges, etc.,. that you would want to participate in the VPN to the VPN domain object on the Checkpoint side and have the corresponding rule. No need to NAT unless there is a requirement to do so such as communicating to a public IP over a VPN or a conflict for overlapping IP Network. Also on the Palo side you will have to allow&amp;nbsp;&lt;SPAN&gt;192.168.88.0/24 or a single IP/32 if&amp;nbsp;that is all you need from that subnet, inbound and make any of other Palo config changes to allow the traffic. Now if you need to NAT for some other reason, you can NAT but will still have the network&amp;nbsp;of individual IP from192.168.88.0/24 in the rule and the VPN domain object on the Checkpoint side.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 19:49:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/CP1570-VPN-S2S-to-Palo-Alto-NAT-translation/m-p/199911#M9934</guid>
      <dc:creator>JoSec</dc:creator>
      <dc:date>2023-12-06T19:49:59Z</dc:date>
    </item>
  </channel>
</rss>

