- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Anyone found a way around the issues I encounter with trying to create the NAT policy?
### Name
I'm unable to set the name of a NAT rule. This is possible manually in Smart Console.
### Position
I'm unable to get rules above the Automatic Generated Rules. This is possible in Smart Console.
I can't use position 1 or 2 because those are for default rules. Can't use 0 as error states must be great equal 1. So when I create the rule on position 3 it is below the others. I really miss an insert above / below position X kinda option. Or a move rule option. That goes for access policies also.
Possibly with check_point.mgmt.cp_mgmt_set_nat_rule and new position option, but zero documentation on if at all and if so how. The fact i have to do it according to the document by "Edit existing object using object name or uid." and the example not showing either doesn't give me a warm feeling ...
### Multiple modules
I can't use state present / absent as with a regular access policy and many other Ansible modules. So have to use cp_mgmt_add_nat_rule AND cp_mgmt_delete_nat_rule, why this difference?
Hi,
Starting from R81 API version 1.7 and later we started supporting to use name in the NAT rule which enables you to create a idempotent module for our ansible collection to add, change and delete NAT rules.
This module has been developed by R&D and is going to be added to Galaxy repository in the next version we release of the collection.
The new module allows you to use relative position such as "top" and "bottom" to overcome the challenges of creating a rule above or below the automatic generated NAT rules in a situation when there is no manual NAT rule already in place in that location.
If you want to find an example on how to use it you can find that here:
(this example uses the relative position "top" to be able to create the first rule in a new NAT rule base above the automatic NAT rule)
Please note as described in the module the management server needs to have a JHF that addresses PMTR-88097
Hi there,
Not sure I understand your poitns 1 and 2. Name can be configured, as well as position.
Andy
If I use name: "name" in my Ansible playbook I get an error stating name isnt valid option for a NAT rule.
Position isn't really position it seems, just a value which must be unique. So if I have
1 - first NAT rule
2 - second NAT rule
3 - third NAT rule
I can only use position 4 (which will put it below 3), if I use any of the other positions I get an error. That is my experience at least.
Oh 81.10 BTW, forgot to add that.
Ok, disregard what I said then, I thought you were strictly referring to smart console.
Andy
Hi,
Starting from R81 API version 1.7 and later we started supporting to use name in the NAT rule which enables you to create a idempotent module for our ansible collection to add, change and delete NAT rules.
This module has been developed by R&D and is going to be added to Galaxy repository in the next version we release of the collection.
The new module allows you to use relative position such as "top" and "bottom" to overcome the challenges of creating a rule above or below the automatic generated NAT rules in a situation when there is no manual NAT rule already in place in that location.
If you want to find an example on how to use it you can find that here:
(this example uses the relative position "top" to be able to create the first rule in a new NAT rule base above the automatic NAT rule)
Please note as described in the module the management server needs to have a JHF that addresses PMTR-88097
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY