Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Serhii_Yaholnyt
Contributor
Jump to solution

Is it possible to NAT traffic only in VPN community?

Customer builds Site-To-Site VPN between Check Point and 3rd party device. VPN domain of 3rd party device overlaps with a network from internal scope so we want to translate it. I saw an option "disable NAT inside VPN community" but I think we want an opposite option: make NAT rule work only if traffic is within VPN community. Is there such possibility?

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Champion
Champion

As long as "disable NAT in VPN Community" is unchecked, traffic entering or leaving a VPN tunnel is subject to the NAT policy just like any other traffic.  To set up NAT for VPN traffic only you'll need to make sure the box is unchecked then set up a manual NAT rule at the top of the NAT policy.  Be sure to set the Original Source and Original Destination Fields as tight and specific as possible to avoid catching unintended traffic in that NAT rule.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com

View solution in original post

1 Reply
Timothy_Hall
Champion
Champion

As long as "disable NAT in VPN Community" is unchecked, traffic entering or leaving a VPN tunnel is subject to the NAT policy just like any other traffic.  To set up NAT for VPN traffic only you'll need to make sure the box is unchecked then set up a manual NAT rule at the top of the NAT policy.  Be sure to set the Original Source and Original Destination Fields as tight and specific as possible to avoid catching unintended traffic in that NAT rule.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events