- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hello,
I have a real virtual Checkpoint Security Gateway setup scenario: carrier who provides the virtual computing platform can only allow one public IP on virtual Checkpoint Security Gateway instance running Checkpoint v80.20, i.e. the internet-facing interface IP, no other public IP range could be allocated due to platform restriction.
The virtual checkpoint SG setup requirements:
1) setup outbound internet access, setup Hide NAT for all internal subnets with the outside interface IP;
2) setup static NAT on FW for inbound access using the same outside interface IP, so remote client VPN access could get to the VPN Concentrator which sits within DMZ behind FW
The questions are: 1) is it doable 2) any FW NAT/Arp/local Port range setup issues; 3) any performance concerns
I haven't setup the test environment yet, I'm wondering if anyone could give some valuable comments/advices.
You should be able to achieve this, provided that you do not have IPSec enabled on Check Point, if your VPN concentrator is using it, or you may have to change the default portal port if you are looking to implement SSL/TLS VPN from behind Check Point.
You can do the first thing easily enough.
The second should be possible depending on the ports required.
That said, the Check Point gateway can also terminate VPN connections (with appropriate licenses).
Thanks for confirmation.
We'll use standalone TLS/DTLS based VPN concentrator, static NAT on Checkpoint Security Gateway, VPN traffic could be directed to box behind FW, port forwarding setup would be applied to both TCP and UDP 443, no http/https services would be enabled on Checkpoint Security Gateway.
Note that there is something called multiportal that may impact usage of TCP 443.
Recommend that you change the Gaia WebUI port to something other than 443.
A couple other changes may be required.
You should be able to achieve this, provided that you do not have IPSec enabled on Check Point, if your VPN concentrator is using it, or you may have to change the default portal port if you are looking to implement SSL/TLS VPN from behind Check Point.
Problem you will be running into is that you cannot NAT ESP traffic and most VPN concentrators really do not like to be NATted.
So I hope for you it will work but I have my doubts.
Not the IPsec based VPN Concentrator for which the NAT-Transversal feature needs be supported for NAT devices in between. We're using the TLS/DTLS based VPN concentrator, NAT with devices in between should not a problem.
Hard to say in regards to performance issues...in my own personal experience, EVERY vendor will tell you how their firewalls work based on MINIMUM requirements and basic setup, so I always take it with a grain of salt : ). Having said that, I would say it is doable and as phoneboy said, setup should work based on ports required. Also, again, just my own personal experience, I had seen where different customers use same setup and gateways and it works for one, but not the other. There are so many factors that can affect this...(network itself, proxy used?, acceleration...)
Yes, literally the setup should work. We'll do some load testing to simulate the large WFH traffic throughput case.
BTW, you may want to locate it in DMZ, create an IPS/AV exception for Internet-to-concentrator, but leave the Anti-bot in place.
You can inspect/control the traffic from concentrator to your internal networks using policies.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 23 | |
| 19 | |
| 10 | |
| 9 | |
| 8 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY