cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted

Is it possible to NAT traffic only in VPN community?

Jump to solution

Customer builds Site-To-Site VPN between Check Point and 3rd party device. VPN domain of 3rd party device overlaps with a network from internal scope so we want to translate it. I saw an option "disable NAT inside VPN community" but I think we want an opposite option: make NAT rule work only if traffic is within VPN community. Is there such possibility?

0 Kudos
1 Solution

Accepted Solutions

Re: Is it possible to NAT traffic only in VPN community?

Jump to solution

As long as "disable NAT in VPN Community" is unchecked, traffic entering or leaving a VPN tunnel is subject to the NAT policy just like any other traffic.  To set up NAT for VPN traffic only you'll need to make sure the box is unchecked then set up a manual NAT rule at the top of the NAT policy.  Be sure to set the Original Source and Original Destination Fields as tight and specific as possible to avoid catching unintended traffic in that NAT rule.

"IPS Immersion Training" Self-paced Video Class
Now Available at http://www.maxpowerfirewalls.com
1 Reply

Re: Is it possible to NAT traffic only in VPN community?

Jump to solution

As long as "disable NAT in VPN Community" is unchecked, traffic entering or leaving a VPN tunnel is subject to the NAT policy just like any other traffic.  To set up NAT for VPN traffic only you'll need to make sure the box is unchecked then set up a manual NAT rule at the top of the NAT policy.  Be sure to set the Original Source and Original Destination Fields as tight and specific as possible to avoid catching unintended traffic in that NAT rule.

"IPS Immersion Training" Self-paced Video Class
Now Available at http://www.maxpowerfirewalls.com