Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
asaivephac
Explorer

NAT on gateway itself for IKE traffic

Hi,

We have a new service provider that we're connected to and their GW is 172.16.0.1/29, on their end they forward all the public network traffic (/28) to the Checkpoint VIP(172.16.0.2/29) and we perform all NAT on our end.

We have hide behind NAT configured on our network objects and that's all working great but the IKE traffic is generated by the gateway itself so it's not getting NAT translation so the provider sees the VIP address and can't route it.

Is there a way to NAT the Gateway itself so IKE appears as a NAT address instead of the 172.16.0.2/29 private interface VIP?

Any thoughts how this can be accomplished?

 

 

0 Kudos
2 Replies
AlekzNet
Contributor

Which device has a public IP-address?

NAT-T should take care of IKE with NAT.

0 Kudos
asaivephac
Explorer

The provider FW has public IP-address and has a rule to forward everything to our VIP and we manage our own NAT translation.

If I were to put a manual NAT-t entry for (CP VIP) 172.16.10.2 > NAT, would the ipsec tunnel use the nat address? I'm not sure if Nat-T is before or after VPN.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events