- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello guys,
i hope i chose the right forum.
We have connected a Cisco ACI to a R80.20 Management System and are using dynamic Datacenter Objects in the Firewall Policy.
sk128612 says that Data Center Objects are not supported in NAT Policy and Network Groups.
This considerably limits the function of the ACI for us.
Will this "known limitation" fixed in the future or is it not possbile from the technical point of view?
I am looking forward to your answers!
Best regards,
Adrian
Hi PhoneBoy,
thank you very much for your reply.
We operate the gateway with multiple VSX Systems as an Internet firewall for the customer.
The basic idea was to use centrally managed ACI data center objects, as we will have a change volume of about 500 changes per month in the future.
The advantage we hoped to get from the ACI in this case is not given, because we have to create a group and the host objects for each EPG that should do for example Hide NAT.
We can use the datacenter objects in the rule base, but not in the NAT rules. This means a lot more work for us in our day-to-day business.
I have attached a screenshot of a typical Data Center Object from the ACI, which should be used for NAT.
Regards,
Adrian
Hi. In the coming R80.40 it is possible to use Data Center objects and Network objects in the same cell in the Access (FW) policy. We also support network group with Data Center objects and Network objects (hybrid group).
Hi PhoneBoy,
sounds easier than it is.
This was only an example group, but not every EPG contains all hosts in the same subnet.
The ACI is managed externally and contains about 15000 EPG objects.
We will receive change request from the customer directly to implement FW rules and NAT rules with the EPG objects.
If we need to manually create each EPG object as a network group on the Check Point when it is to be used in a NAT rule and have to maintain this manually with each change on the ACI, we will have a lot of overhead.
Especially when receiving about 400 change requests a month, once the customer is productive.
I can totally understand your technical point of view, that the Access Policy will be applied before the NAT Rules and will regulate all the traffic going outbound. But we are here located in germany and the customer also, and this is all laid down in contracts, that each Access rule and also NAT rule is as precise as possible.
I hope you can understand now, which problem I am facing.
Regards
Adrian
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Thu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 10:00 AM (CEST)
Schutz souveräner Workloads: Check Point & die AWS European Sovereign CloudThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY