- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hi,
We have single checkpoint gateway installed in Azure environment. We want to do static NAT so that some IPs are publicly available but don't want to use gateway IP as a PAT.
I have attached one more IP to external interface of firewall which has public IP and followed steps given as below.
https://community.checkpoint.com/t5/CloudGuard-IaaS/STATIC-NAT-in-Azure-Checkpoint/td-p/75730
Done NAT configuration like below
Original source Original Dest Xlate source Xlate Des
Any 172.17.1.8 Any 172.17.7.24
Please note that 172.17.1.8 has public IP and this NATing will be taken care by Azure. when I am trying to test traffic from outside, I am getting proper logs but not able to connect end machine 172.17.7.24. Please see logs.
Does anyone has any idea why it is not working. any setting is missing on firewall or azure side?
@Gaurav_Pandya , if you have set up only a unidirectional manual NAT rules, it'll result in the behavior you are describing. Disable that rule and change the NAT properties of the object to configure static NAT.
Vladimir
Hi Vladimir.
Thanks for your response. I am doing manual NAT because I will map multiple IPs to public IP with different ports in future.
For testing purpose, I have done Object NAT as well but still it is not working. May be I am missing something on Azure side?
how is the NSG configured on the external side of the Check Point?
Hi All,
Issue is resolved. There was no firewall configuration issue. It is the Azure security group which is blocking traffic. 😊
Hi Gaurav,
Am facing same issue.
Can you tell me what configuration you did the Security Group.
Regards,
Mitesh
Hi Mitesh,
You can define security group or ACL for each subnet in Azure, where you will define which source IP/subnet will access this subnet with particular port. So you need to open flow in security group or ACL as well.
Hi Gaurav,
Thanks for the reply.
Just want to confirm, post assigning secondary interface to Checkpoint VM in Azure portal. Does we have attach secondary interface in Checkpoint topology as a external interface.
Regards,
Mitesh
No. You do not need to add anything on Checkpoint except required NAT rule and policy.
Please note that we are using single gateway.
Hi Gaurav,
Am new in Azure.
We have deployed Checkpoint in Standalone mode.
Recently we added secondary ip address to Checkpoint External Interface.
| Private IP | Public IP | |
| Primary | 10.10.10.2 | 2.2.2.2 |
| Secondary | 10.10.10.3 | 3.3.3.3 |
Internal Server IP = 10.10.20.100
Our Requirement:-
We want to do Static NAT using Secondary Public IP. For that we created NAT & Firewall Policy as below.
Nat Policy:-
| Original Src | Original Dst | Original Service | Translated Src | Translated Dst | Translated Service |
| Any | 10.10.10.3 | Any | Original | 10.10.20.100 | Any |
| 10.10.20.100 | Any | Any | 10.10.10.3 | Original | Any |
Firewall Policy:-
| Source | Destination | Service | Action |
| Any | 3.3.3.3 | Any | Accept |
| 10.10.10.3 |
Hope till now am on right track.
Can you tell me what configuration needs to be done in Azure side.
Regards,
Mitesh Nandu
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Thu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 10:00 AM (CEST)
Schutz souveräner Workloads: Check Point & die AWS European Sovereign CloudThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY