- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hello,
I am configuring a Check Point firewall with two internet links in Load Sharing mode using ISP Redundancy. The NAT is set up on the internal network objects using the "Hide Behind Gateway"
I have the following questions:
How does NAT function in Load Sharing mode?
Does the firewall apply Hide NAT based on the active ISP interface for each connection?
Are static NAT rules ignored in this mode?
Is it possible to use a SNAT Pool with ISP Redundancy in Load Sharing mode?
Can I configure a pool of public IPs for outgoing connections, ensuring that traffic is NATed to the appropriate public IP based on the active ISP link?
This is what AI Copilot has to say for the matter:
Here are detailed answers to your questions about NAT and ISP Redundancy in Load Sharing mode on Check Point firewalls:
Summary Table
| Scenario | Supported? | Notes |
|---|---|---|
| Hide NAT per ISP | Yes | NATs to interface IP of egress ISP |
| Static NAT in Load Sharing | Yes | Required for incoming connections |
| SNAT Pool (native) | No | Workarounds possible with manual NAT and dynamic objects |
| Pool of public IPs per ISP | Possible (manual) | Requires advanced configuration and scripting (see SK174197) |
If you need step-by-step guidance for a specific advanced NAT pool scenario, let me know your exact requirements and I can provide more detailed instructions!
You got it, makes total sense.
Andy
This is what AI Copilot has to say for the matter:
Here are detailed answers to your questions about NAT and ISP Redundancy in Load Sharing mode on Check Point firewalls:
Summary Table
| Scenario | Supported? | Notes |
|---|---|---|
| Hide NAT per ISP | Yes | NATs to interface IP of egress ISP |
| Static NAT in Load Sharing | Yes | Required for incoming connections |
| SNAT Pool (native) | No | Workarounds possible with manual NAT and dynamic objects |
| Pool of public IPs per ISP | Possible (manual) | Requires advanced configuration and scripting (see SK174197) |
If you need step-by-step guidance for a specific advanced NAT pool scenario, let me know your exact requirements and I can provide more detailed instructions!
On top, I would also add sk42636 and all other SKs referenced there.
Thank You @_Val_ !
I guess the best way is to implement SD-WAN in this case.
My customer has too many diferent rules with DIfferent Source IPs and wants to use both ISP links.
You got it, makes total sense.
Andy
With Quantum SD-WAN You can achieve all that in a much simpler way including using SNAT pool per ISP with load sharing per traffic (user/src/dst/updatable obj, application, etc)
Also Quantum SD-WAN will still accelerate those connections, in oppose to ISP Redundancy Load sharing that uses slow path AFAIK.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 75 | |
| 17 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Thu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 10:00 AM (CEST)
Schutz souveräner Workloads: Check Point & die AWS European Sovereign CloudThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY