<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Check Point Automatic NAT Conversion in Expedition Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/expedition-discussions/check-point-automatic-nat-conversion/m-p/457126#M3804</link>
    <description>&lt;P&gt;Expedition: 1.2.3&lt;/P&gt;
&lt;P&gt;Source configs: Check Point R80.30 HFA236&lt;/P&gt;
&lt;P&gt;Target configs: Panorama / PAN-OS 10.1.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone had success [easily] converting Check Point automagic NATs in Expedition? I've had to manually modify both static and hide NATs and create new objects for the translated addresses as the imported rules reference the original object ("valid address" in CP speak) because no explicit object exists for the translation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've reached a point where I can no longer select an object for a DIPP translated address - even the original object in the rule doesn't appear in the dropdown:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mb_equate_1-1641428544550.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38526i5DCD29754ABE5769/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mb_equate_1-1641428544550.png" alt="mb_equate_1-1641428544550.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't work out where I've gone wrong, as the same objects are available in the original packet source field:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mb_equate_2-1641428665612.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38527i7D522F1FAAD38003/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mb_equate_2-1641428665612.png" alt="mb_equate_2-1641428665612.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some things to note...&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The CP policy, when imported, appears in a vsys or device group "Management server-[policy_package_name]"&lt;/LI&gt;
&lt;LI&gt;The CP objects appear in a different device group "[policy_package_name] Security"
&lt;UL&gt;
&lt;LI&gt;Why the different device group?&lt;/LI&gt;
&lt;LI&gt;Naturally the objects in the policy are orphaned and cannot be referenced until they are converted to Shared&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;New objects are created in the device group selected in the Dynamic Toolbar
&lt;UL&gt;
&lt;LI&gt;As above, objects must be converted to Shared if not created in the same device group as the policy&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jan 2022 00:36:43 GMT</pubDate>
    <dc:creator>mb_equate</dc:creator>
    <dc:date>2022-01-06T00:36:43Z</dc:date>
    <item>
      <title>Check Point Automatic NAT Conversion</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/check-point-automatic-nat-conversion/m-p/457126#M3804</link>
      <description>&lt;P&gt;Expedition: 1.2.3&lt;/P&gt;
&lt;P&gt;Source configs: Check Point R80.30 HFA236&lt;/P&gt;
&lt;P&gt;Target configs: Panorama / PAN-OS 10.1.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone had success [easily] converting Check Point automagic NATs in Expedition? I've had to manually modify both static and hide NATs and create new objects for the translated addresses as the imported rules reference the original object ("valid address" in CP speak) because no explicit object exists for the translation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've reached a point where I can no longer select an object for a DIPP translated address - even the original object in the rule doesn't appear in the dropdown:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mb_equate_1-1641428544550.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38526i5DCD29754ABE5769/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mb_equate_1-1641428544550.png" alt="mb_equate_1-1641428544550.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't work out where I've gone wrong, as the same objects are available in the original packet source field:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mb_equate_2-1641428665612.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38527i7D522F1FAAD38003/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mb_equate_2-1641428665612.png" alt="mb_equate_2-1641428665612.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some things to note...&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The CP policy, when imported, appears in a vsys or device group "Management server-[policy_package_name]"&lt;/LI&gt;
&lt;LI&gt;The CP objects appear in a different device group "[policy_package_name] Security"
&lt;UL&gt;
&lt;LI&gt;Why the different device group?&lt;/LI&gt;
&lt;LI&gt;Naturally the objects in the policy are orphaned and cannot be referenced until they are converted to Shared&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;New objects are created in the device group selected in the Dynamic Toolbar
&lt;UL&gt;
&lt;LI&gt;As above, objects must be converted to Shared if not created in the same device group as the policy&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 00:36:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/check-point-automatic-nat-conversion/m-p/457126#M3804</guid>
      <dc:creator>mb_equate</dc:creator>
      <dc:date>2022-01-06T00:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Automatic NAT Conversion</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/check-point-automatic-nat-conversion/m-p/457129#M3805</link>
      <description>&lt;P&gt;Update: I've been able to reference new objects created in the same device group as the policy, just not shared, and this only applies to the Translated Address field for DIPP rules (statics are not affected).&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 00:47:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/check-point-automatic-nat-conversion/m-p/457129#M3805</guid>
      <dc:creator>mb_equate</dc:creator>
      <dc:date>2022-01-06T00:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Automatic NAT Conversion</title>
      <link>https://live.paloaltonetworks.com/t5/expedition-discussions/check-point-automatic-nat-conversion/m-p/457131#M3806</link>
      <description>&lt;P&gt;Update 2: Solution! If the referenced object is not in the same DG as the policy (e.g. Shared), "all" must be selected in the dynamic toolbar for those objects to be visible (again only for DIPP translated addresses).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is one minor limitation though - Multi Edit does not work in the "all" device group so such rules must be manually edited.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bug I reckon.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jan 2022 00:54:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/expedition-discussions/check-point-automatic-nat-conversion/m-p/457131#M3806</guid>
      <dc:creator>mb_equate</dc:creator>
      <dc:date>2022-01-06T00:54:25Z</dc:date>
    </item>
  </channel>
</rss>

