Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
WarrenJ1
Explorer

Manual NAT with Port Forwarding on Check Point Virtual GW

Hi Team,

We have configured the public IP segment 71.56.98.x/28 on the Check Point firewall WAN interface (eth1).

Our requirement is to perform manual NAT with port forwarding for one of our internal servers. We are using one available public IP from the above subnet and mapping it to the internal server 10.20.30.40, with the following requirement:

  • External Port: 443 Internal
  • Destination: 10.20.30.40:8443

However, we are facing the following issue:

  • When configuring Static NAT (manual NAT), the setup is not working
  • When using Automatic NAT, it is working, but we are unable to perform port forwarding (443 → 8443)

Could you please help us understand:

  1. Why manual NAT is not working in this scenario
  2. The correct way to configure port forwarding using manual NAT in Check Point

Kindly assist with the correct configuration or any prerequisites we may be missing.

Thanks & Regards,

Warren

mp3 juice
0 Kudos
3 Replies
PhoneBoy
Admin
Admin

Automatic NAT will create the necessary proxy ARPs for NAT to work.
In manual NAT, you also have to configure a proxy ARP: https://support.checkpoint.com/results/sk/sk30197 

0 Kudos
Lesley
MVP Gold
MVP Gold

This is correct. Automatic NAT = you don't need to make proxy arp. With manual NAT you have to make proxy arp (unless you use IP that is configured on firewall interface). If you don't see the traffic in your traffic logs it is arp issue. You can confirm this by doing tcpdump on external interface. There you would see ARP request, who has IP XXX? And then no one will reply. With proxy arp the firewall reply and then the traffic will flow 

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
Martijn
MVP
MVP

Hi,

Can you show us the configured access rules and NAT rules you have configured for this traffic?

You mention NAT is working but unable to connect to the server. Is routing to the destination OK?
Maybe anti-spoofing on the internal interface for the return traffic?

What does the logs show?

Martijn

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events