- CheckMates
- :
- Products
- :
- Quantum
- :
- SmartMove
- :
- Re: Can't use groups with exclusion in NAT rules i...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can't use groups with exclusion in NAT rules in R80?
In R80 can you not use groups with exclusion in NAT rules?
In a ruleset imported from R77 - where it has verified OK for years - am getting multiple verification errors:
Invalid Object 'XXXXX' in Original Source of Address Translation Rule 195. The valid objects are: host, gateway, network, address range and router.
The original source in that rule is a group with exclusion. Is that no longer supported?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The valid objects are: host, gateway, network, address range and router.
Groups are not listed as valid objects at all in that verify message.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The fact that it worked at all in prior releases is considered a bug that has since been fixed.
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the prompt response.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is unfortunate this was categorised as a bug as it is useful functionality.
Applying a NAT rule to a set of things except for a subset of those things is required sometimes.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I try this with our VPN addresses to and internal segment of our LAN and after I push policy I can no longer ping the network the destination network...does anyone have thoughts on that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
But if you use SmartMove tool (sk97246) for Juniper to Check Point conversion, it will happily create NAT rules using groups with exclusion; I think if you decided it's a bug in one place you should not use it in another as a feature (otherwise this tool is very handy, btw, thanks).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That might be a bug in the SmartMove tool.
Paging @yael_haker
I'm actually curious now if rules with negated objects in NAT rules works in R81, since we made major changes to the NAT policy in this version.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No. In R81, NAT supports domain objects, security zones, updatable objects, access roles, data centers and hit count.
But not negate objects / group with exclusions.
As you wrote before, it can be achieved using no NAT rule.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Meital_Natanson is there a way to test NAT rule matching from the CLI gateway similar to fw up_execute for the Firewall/Network policy layer?
March 27th with sessions for both the EMEA and Americas time zones
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Timothy_Hall - no such option.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If there are issues with SmartMove - please contact us at sc@checkpoint.com
We will appreciate to get a copy of the config file in order to address this issue
