- Products
- Learn
- Local User Groups
- Partners
- More
Stop Babysitting Rules.
Go Agentic
Step Into the Future of
AI-Powered Cyber Security
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hello
A week or so ago we changed an ip address on one of our interfaces from 10.157.1.10 to 10.184.0.2 we also changed the NAT rules that was configured to the old ip address.
But now still the firewall sends packets with the old ip of 10.157.1.10 and 12 even when those addreses are unconfigured.
Running R80.20 with HFA 103
//Johan
Please provide a log screenshot of accepted traffic still being NATted to the old address, the log card will show the NAT rules involved. Keep in mind that after changing a NAT address only new connections will start using it, old connections will continue using the old NAT address until they end. Are sure you are launching NEW connections for testing and not still riding on old ones?
Yes its a VSX cluster with two physical GWs and two VSes, the change was made in SmartConsole.
//Johan
Yes we have pushed VS policy several times and the cluster policy once now, but still the old ip address is used.
//Johan
Any chance you have proxy arp in place?
Yes the automatic default Proxy ARP is enabled and the Merge Manual setting too, however in the local.arp file there is only one entry with the new ip address in it.
//Johan
Please provide a log screenshot of accepted traffic still being NATted to the old address, the log card will show the NAT rules involved. Keep in mind that after changing a NAT address only new connections will start using it, old connections will continue using the old NAT address until they end. Are sure you are launching NEW connections for testing and not still riding on old ones?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 34 | |
| 22 | |
| 11 | |
| 9 | |
| 7 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 4 |
Thu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaThu 04 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E9: READY OR NOT: Securing the AI Enterprise 1/5 - AI Agent SecurityWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaThu 04 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E9: READY OR NOT: Securing the AI Enterprise 1/5 - AI Agent SecurityWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY