- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- NAT in S2S VPN deployment.
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
NAT in S2S VPN deployment.
Hello,
A query, I have a S2S IPsec VPN against a third party, in which, on our side we have the need that "the remote peer" does not know us with the real IPs of our servers.
These are our Real IPs:
10.7.12.124
10.7.106.114
192.168.216.50
Destination IP of the remote peer:
69.20.50.41
These 3 IPs, must "present" themselves to the remote peer, with the NAT IP -> 172.26.15.254
Checkpoint requires that in this case, 3 Hide NAT type rules are created for each of the real IPs, right?
It is not possible to work it in only one NAT rule?
Cheers. 🙂
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, it is possible to setup groups in the NAT rule base for your hide NAT. I use this feature quite often.
You can absolutely put those 3 servers into a group and specify hide behind 172.26.15.254 when talking to the other remote network.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey bro,
Make sure NAT is enabled inside vpn community and if its static nat rules, then they may need to be separate.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Buddy
The TAC told me that in order for Checkpoint, to take my manual NAT rules into account, I have to disable the checkbox of the option that you see in the following image. 😄
For now, my manual NAT works fine, but it is configured as a 1 - 1 NAT.
And what I want is that on my side, there are 3 servers with different IPs, that can reach the other side of the VPN, with a single NAT IP.
Is it possible to make a Hide NAT, using as origin a "group object" and putting there, all the IPs that I want to leave my side ????
Greetings.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sorry, my bad, I believe TAC is correct. Also, as per below, makes sense
VPN Communities - Advanced (checkpoint.com)
Btw, if its hide NAT rule, then group should work.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, it is possible to setup groups in the NAT rule base for your hide NAT. I use this feature quite often.
You can absolutely put those 3 servers into a group and specify hide behind 172.26.15.254 when talking to the other remote network.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
100% that works, agree.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the support, guys.
Cheers. 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FYBFOC = for you bro, free of charge 🙂
