- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: NAT on gateway itself for IKE traffic
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
NAT on gateway itself for IKE traffic
Hi,
We have a new service provider that we're connected to and their GW is 172.16.0.1/29, on their end they forward all the public network traffic (/28) to the Checkpoint VIP(172.16.0.2/29) and we perform all NAT on our end.
We have hide behind NAT configured on our network objects and that's all working great but the IKE traffic is generated by the gateway itself so it's not getting NAT translation so the provider sees the VIP address and can't route it.
Is there a way to NAT the Gateway itself so IKE appears as a NAT address instead of the 172.16.0.2/29 private interface VIP?
Any thoughts how this can be accomplished?
- Labels:
-
NAT
-
Site to Site VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which device has a public IP-address?
NAT-T should take care of IKE with NAT.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The provider FW has public IP-address and has a rule to forward everything to our VIP and we manage our own NAT translation.
If I were to put a manual NAT-t entry for (CP VIP) 172.16.10.2 > NAT, would the ipsec tunnel use the nat address? I'm not sure if Nat-T is before or after VPN.
