- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
01-05-2022 04:36 PM
Expedition: 1.2.3
Source configs: Check Point R80.30 HFA236
Target configs: Panorama / PAN-OS 10.1.3
Has anyone had success [easily] converting Check Point automagic NATs in Expedition? I've had to manually modify both static and hide NATs and create new objects for the translated addresses as the imported rules reference the original object ("valid address" in CP speak) because no explicit object exists for the translation.
I've reached a point where I can no longer select an object for a DIPP translated address - even the original object in the rule doesn't appear in the dropdown:
I can't work out where I've gone wrong, as the same objects are available in the original packet source field:
Some things to note...
Any ideas?
01-05-2022 04:54 PM
Update 2: Solution! If the referenced object is not in the same DG as the policy (e.g. Shared), "all" must be selected in the dynamic toolbar for those objects to be visible (again only for DIPP translated addresses).
There is one minor limitation though - Multi Edit does not work in the "all" device group so such rules must be manually edited.
Bug I reckon.
01-05-2022 04:47 PM
Update: I've been able to reference new objects created in the same device group as the policy, just not shared, and this only applies to the Translated Address field for DIPP rules (statics are not affected).
01-05-2022 04:54 PM
Update 2: Solution! If the referenced object is not in the same DG as the policy (e.g. Shared), "all" must be selected in the dynamic toolbar for those objects to be visible (again only for DIPP translated addresses).
There is one minor limitation though - Multi Edit does not work in the "all" device group so such rules must be manually edited.
Bug I reckon.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!