<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NAT Help: How to NAT to &amp;quot;Remote&amp;quot; internal subnets (not directly connected) on a 2500 Appliance? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Help-How-to-NAT-to-quot-Remote-quot-internal-subnets-not/m-p/273868#M104278</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I’m running into a bit of a routing/NAT challenge on a &lt;STRONG&gt;Check Point 2500 Security Gateway (R82.00.05)&lt;/STRONG&gt; and could use some collective wisdom.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Scenario:&lt;/STRONG&gt; I need to set up Static NAT for a few internal servers. Usually, this is straightforward when the servers are in a direct LAN segment. However, these specific servers live in a different building/VLAN that is &lt;STRONG&gt;routed&lt;/STRONG&gt; to the Check Point via a core switch.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Checkpoint Internal IP:&lt;/STRONG&gt; 10.0.1.1/24&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Target Server IP:&lt;/STRONG&gt; 192.168.50.10 (reachable via a static route/OSPF pointing to a core switch at 10.0.1.2)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Goal:&lt;/STRONG&gt; Map a Public IP (1.1.1.10) to the Internal Server (192.168.50.10).&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;The Problem:&lt;/STRONG&gt; When I configure the NAT rule and the Host object, the traffic seems to die at the gateway. I suspect the issue is related to &lt;STRONG&gt;Proxy ARP&lt;/STRONG&gt; or the gateway not knowing how to handle the "non-local" destination for a NATed packet.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;A few specific questions for the experts:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Since the target IP isn't on a local interface, do I still need a manual Proxy ARP entry for the Public IP?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Is there a specific setting in the &lt;STRONG&gt;NAT tab&lt;/STRONG&gt; of the Host object (like "Install on Gateway") that I should be wary of in a routed environment?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Do I need to create a "dummy" interface or use a specific Routing/NAT trick to make the 2500 realize it should forward that translated packet back to the core switch instead of looking for it on the local wire?&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I’ve checked the logs in SmartConsole, and I see the hits, but no return traffic. Any advice on the "Check Point way" to handle NAT for remote internal subnets would be greatly appreciated&lt;/P&gt;</description>
    <pubDate>Fri, 20 Mar 2026 07:23:08 GMT</pubDate>
    <dc:creator>Dimitar139594</dc:creator>
    <dc:date>2026-03-20T07:23:08Z</dc:date>
    <item>
      <title>NAT Help: How to NAT to "Remote" internal subnets (not directly connected) on a 2500 Appliance?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Help-How-to-NAT-to-quot-Remote-quot-internal-subnets-not/m-p/273868#M104278</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I’m running into a bit of a routing/NAT challenge on a &lt;STRONG&gt;Check Point 2500 Security Gateway (R82.00.05)&lt;/STRONG&gt; and could use some collective wisdom.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Scenario:&lt;/STRONG&gt; I need to set up Static NAT for a few internal servers. Usually, this is straightforward when the servers are in a direct LAN segment. However, these specific servers live in a different building/VLAN that is &lt;STRONG&gt;routed&lt;/STRONG&gt; to the Check Point via a core switch.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Checkpoint Internal IP:&lt;/STRONG&gt; 10.0.1.1/24&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Target Server IP:&lt;/STRONG&gt; 192.168.50.10 (reachable via a static route/OSPF pointing to a core switch at 10.0.1.2)&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Goal:&lt;/STRONG&gt; Map a Public IP (1.1.1.10) to the Internal Server (192.168.50.10).&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;The Problem:&lt;/STRONG&gt; When I configure the NAT rule and the Host object, the traffic seems to die at the gateway. I suspect the issue is related to &lt;STRONG&gt;Proxy ARP&lt;/STRONG&gt; or the gateway not knowing how to handle the "non-local" destination for a NATed packet.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;A few specific questions for the experts:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;Since the target IP isn't on a local interface, do I still need a manual Proxy ARP entry for the Public IP?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Is there a specific setting in the &lt;STRONG&gt;NAT tab&lt;/STRONG&gt; of the Host object (like "Install on Gateway") that I should be wary of in a routed environment?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Do I need to create a "dummy" interface or use a specific Routing/NAT trick to make the 2500 realize it should forward that translated packet back to the core switch instead of looking for it on the local wire?&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I’ve checked the logs in SmartConsole, and I see the hits, but no return traffic. Any advice on the "Check Point way" to handle NAT for remote internal subnets would be greatly appreciated&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2026 07:23:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Help-How-to-NAT-to-quot-Remote-quot-internal-subnets-not/m-p/273868#M104278</guid>
      <dc:creator>Dimitar139594</dc:creator>
      <dc:date>2026-03-20T07:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Help: How to NAT to "Remote" internal subnets (not directly connected) on a 2500 A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Help-How-to-NAT-to-quot-Remote-quot-internal-subnets-not/m-p/273871#M104281</link>
      <description>&lt;P&gt;No to all of the above. How are you doing the NAT? You shouldn't have to adjust anything, really. Think of what the IP headers are on the packet pre- and post-NAT and make sure the routing across the rest of the network will send the return packet back to the gateway.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2026 08:18:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Help-How-to-NAT-to-quot-Remote-quot-internal-subnets-not/m-p/273871#M104281</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-03-20T08:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Help: How to NAT to "Remote" internal subnets (not directly connected) on a 2500 A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Help-How-to-NAT-to-quot-Remote-quot-internal-subnets-not/m-p/273885#M104287</link>
      <description>&lt;P&gt;The outgoing traffic of the hosts on the remote networks is routed correctly - they have Internet access with "Hide internal networks behind the gateway's external IP address" enabled&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried both with standard Server forwarding rules and manual NAT. Also added firewall rules to accept traffic from and to the remote networks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traffic reaches the WAN interface but does is not sent out on the LAN interface.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2026 12:58:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Help-How-to-NAT-to-quot-Remote-quot-internal-subnets-not/m-p/273885#M104287</guid>
      <dc:creator>Dimitar139594</dc:creator>
      <dc:date>2026-03-20T12:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Help: How to NAT to "Remote" internal subnets (not directly connected) on a 2500 A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Help-How-to-NAT-to-quot-Remote-quot-internal-subnets-not/m-p/273926#M104317</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;
&lt;P&gt;I'm not sure what is a flow here but I definitely see possible problematic points that I would advise to check. First, you don't need to set any proxyARP if you do static NAT as you described (creating a host object and setting static NAT within). Your remote internal host must have the same flow of static NAT. Check that your rulebase is not dropping that connection. Finally, trace route or tcpdump can help you))) Good luck!! BTW, if this is always one way servers call, you can use hide NAT on origin&lt;/P&gt;</description>
      <pubDate>Sat, 21 Mar 2026 18:49:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Help-How-to-NAT-to-quot-Remote-quot-internal-subnets-not/m-p/273926#M104317</guid>
      <dc:creator>NikitaOstrovsky</dc:creator>
      <dc:date>2026-03-21T18:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: NAT Help: How to NAT to "Remote" internal subnets (not directly connected) on a 2500 A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Help-How-to-NAT-to-quot-Remote-quot-internal-subnets-not/m-p/273959#M104331</link>
      <description>&lt;P&gt;In theory, if we are allowing inbound traffic from the internet here, all you should need here is a rule in the policy allowing access to the network host object for that server, then inside that host object configure your static NAT IP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2026 03:32:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NAT-Help-How-to-NAT-to-quot-Remote-quot-internal-subnets-not/m-p/273959#M104331</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-03-23T03:32:30Z</dc:date>
    </item>
  </channel>
</rss>

