- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello team ;-),
Writing today because I have an issue related to Updtabale object in Quantum Sparck appliance.
Model is 1550
Running R81 (996000575)
Remotely manage by MDM R81.10.
I could reduce policy in 2 Sections:
1. Allowing access to/from the global entreprise network without NAT or anything (appliance is connected behind SDWAN devices). (let's say 192.168.1.0/24 to/from 192.168.2.0/24)
2. Allowing access to UO: Zscaler Services and for sure NAT with external ip.
I had some complaints from some users that sometimes servers raise a "disconnected" status.
Looking at the logs in the Dashboard, What I see is unbelievable (not the real ip in the post...):
Src: 192.168.1.2 (this is an internal host)
Dst: 192.168.2.2 (this is an ip remotely connected with SDWAN) AND the UO:"Zscaler Services".
And so the src is natted and for sure connection is not possible. Dst should be only 192.168.2.2 and NO NAT.
I have checked the .C file for Zscaler and for sure 192.198.2.2 is not in it.
Any clue ?
Thanks,
Im slightly confused, so just want to make sure Im getting this...are you saying src is natted and that part is fine, but also dst shows nat, but should NOT be?
Best,
Andy
I should reach 192.168.2.2 from 192.168.1.2. Policy is allowing this traffic. From / to these network no nat is required. It is part of the global entreprise network.
Sometimes, when I reach 192.168.2.2, in the Dst section of the logs I have: "192.168.2.2" AND "Zscaler services". As if 192.168.2.2 was part of "Zscaler Services" object while it is not. Traffic is using external interface and is NATted while it should use another routing interface without NAT.
Rgds,
I see what you mean, now I got it. Can you verify route is correct?
Routing is fine. Sometimes it is working, sometimes not.
Sounds like you may need remote with TAC to check this further, hard to say for sure why thats happenind, sorry.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY