<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Manual NAT with Port Forwarding on Check Point Virtual GW in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-Port-Forwarding-on-Check-Point-Virtual-GW/m-p/275551#M104959</link>
    <description>&lt;P&gt;Automatic NAT will create the necessary proxy ARPs for NAT to work.&lt;BR /&gt;In manual NAT, you also have to configure a proxy ARP:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk30197" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk30197&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Apr 2026 16:06:05 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2026-04-15T16:06:05Z</dc:date>
    <item>
      <title>Manual NAT with Port Forwarding on Check Point Virtual GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-Port-Forwarding-on-Check-Point-Virtual-GW/m-p/275481#M104928</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We have configured the public IP segment 71.56.98.x/28 on the Check Point firewall WAN interface (eth1).&lt;/P&gt;&lt;P&gt;Our requirement is to perform manual NAT with port forwarding for one of our internal servers. We are using one available public IP from the above subnet and mapping it to the internal server 10.20.30.40, with the following requirement:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;External Port: 443 Internal&lt;/LI&gt;&lt;LI&gt;Destination: 10.20.30.40:8443&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;However, we are facing the following issue:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When configuring Static NAT (manual NAT), the setup is not working&lt;/LI&gt;&lt;LI&gt;When using Automatic NAT, it is working, but we are unable to perform port forwarding (443 → 8443)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Could you please help us understand:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Why manual NAT is not working in this scenario&lt;/LI&gt;&lt;LI&gt;The correct way to configure port forwarding using manual NAT in Check Point&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Kindly assist with the correct configuration or any prerequisites we may be missing.&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards,&lt;/P&gt;&lt;P&gt;Warren&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 07:05:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-Port-Forwarding-on-Check-Point-Virtual-GW/m-p/275481#M104928</guid>
      <dc:creator>WarrenJ1</dc:creator>
      <dc:date>2026-04-15T07:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT with Port Forwarding on Check Point Virtual GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-Port-Forwarding-on-Check-Point-Virtual-GW/m-p/275551#M104959</link>
      <description>&lt;P&gt;Automatic NAT will create the necessary proxy ARPs for NAT to work.&lt;BR /&gt;In manual NAT, you also have to configure a proxy ARP:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk30197" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk30197&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 16:06:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-Port-Forwarding-on-Check-Point-Virtual-GW/m-p/275551#M104959</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-04-15T16:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT with Port Forwarding on Check Point Virtual GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-Port-Forwarding-on-Check-Point-Virtual-GW/m-p/275559#M104964</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Can you show us the configured access rules and NAT rules you have configured for this traffic?&lt;BR /&gt;&lt;BR /&gt;You mention NAT is working but unable to connect to the server. Is routing to the destination OK?&lt;BR /&gt;Maybe anti-spoofing on the internal interface for the return traffic?&lt;BR /&gt;&lt;BR /&gt;What does the logs show?&lt;BR /&gt;&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 16:57:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-Port-Forwarding-on-Check-Point-Virtual-GW/m-p/275559#M104964</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2026-04-15T16:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT with Port Forwarding on Check Point Virtual GW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-Port-Forwarding-on-Check-Point-Virtual-GW/m-p/275561#M104965</link>
      <description>&lt;P&gt;This is correct. Automatic NAT = you don't need to make proxy arp. With manual NAT you have to make proxy arp (unless you use IP that is configured on firewall interface). If you don't see the traffic in your traffic logs it is arp issue. You can confirm this by doing tcpdump on external interface. There you would see ARP request, who has IP XXX? And then no one will reply. With proxy arp the firewall reply and then the traffic will flow&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2026 17:17:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-Port-Forwarding-on-Check-Point-Virtual-GW/m-p/275561#M104965</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-04-15T17:17:15Z</dc:date>
    </item>
  </channel>
</rss>

