- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hello,
I am configuring a Check Point firewall with two internet links in Load Sharing mode using ISP Redundancy. The NAT is set up on the internal network objects using the "Hide Behind Gateway"
I have the following questions:
How does NAT function in Load Sharing mode?
Does the firewall apply Hide NAT based on the active ISP interface for each connection?
Are static NAT rules ignored in this mode?
Is it possible to use a SNAT Pool with ISP Redundancy in Load Sharing mode?
Can I configure a pool of public IPs for outgoing connections, ensuring that traffic is NATed to the appropriate public IP based on the active ISP link?
This is what AI Copilot has to say for the matter:
Here are detailed answers to your questions about NAT and ISP Redundancy in Load Sharing mode on Check Point firewalls:
Summary Table
| Scenario | Supported? | Notes |
|---|---|---|
| Hide NAT per ISP | Yes | NATs to interface IP of egress ISP |
| Static NAT in Load Sharing | Yes | Required for incoming connections |
| SNAT Pool (native) | No | Workarounds possible with manual NAT and dynamic objects |
| Pool of public IPs per ISP | Possible (manual) | Requires advanced configuration and scripting (see SK174197) |
If you need step-by-step guidance for a specific advanced NAT pool scenario, let me know your exact requirements and I can provide more detailed instructions!
You got it, makes total sense.
Andy
This is what AI Copilot has to say for the matter:
Here are detailed answers to your questions about NAT and ISP Redundancy in Load Sharing mode on Check Point firewalls:
Summary Table
| Scenario | Supported? | Notes |
|---|---|---|
| Hide NAT per ISP | Yes | NATs to interface IP of egress ISP |
| Static NAT in Load Sharing | Yes | Required for incoming connections |
| SNAT Pool (native) | No | Workarounds possible with manual NAT and dynamic objects |
| Pool of public IPs per ISP | Possible (manual) | Requires advanced configuration and scripting (see SK174197) |
If you need step-by-step guidance for a specific advanced NAT pool scenario, let me know your exact requirements and I can provide more detailed instructions!
On top, I would also add sk42636 and all other SKs referenced there.
Thank You @_Val_ !
I guess the best way is to implement SD-WAN in this case.
My customer has too many diferent rules with DIfferent Source IPs and wants to use both ISP links.
You got it, makes total sense.
Andy
With Quantum SD-WAN You can achieve all that in a much simpler way including using SNAT pool per ISP with load sharing per traffic (user/src/dst/updatable obj, application, etc)
Also Quantum SD-WAN will still accelerate those connections, in oppose to ISP Redundancy Load sharing that uses slow path AFAIK.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 19 | |
| 10 | |
| 9 | |
| 8 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 4 |
Wed 20 May 2026 @ 11:00 AM (CEST)
The New DDoS Reality: Autonomy, Scale, and the Future of DefenceFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesWed 20 May 2026 @ 11:00 AM (CEST)
The New DDoS Reality: Autonomy, Scale, and the Future of DefenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY