- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Hi,
I want to make Nat Rule for redundancy ISP for out going traffic. I have 2 ISP and Objects are Statically nated with their respective IP from ISP.I want configure a fail over nat rule. Is it possible or any other solution will be help full.
* ISPs are terminated in a Cisco Wan Switch and Checkpoint is connected directly with Wan Switch.
GW version 81.20
Is it a single ISP or the same ISP with two different NAT numbers?
If they are different ISPs, you should be able to accomplish this via ISP Redundancy.
See: https://support.checkpoint.com/results/sk/sk34812
Otherwise, you should use a Dynamic Object in your NAT rule instead (which is what ISP Redundancy ultimately does).
You'll need to write a script to update the contents of this Dynamic Object using the dynamic_objects CLI command on each gateway that uses this object.
However, this gives you flexibility as to how and when to "fail over" the NAT.
Is it a single ISP or the same ISP with two different NAT numbers?
If they are different ISPs, you should be able to accomplish this via ISP Redundancy.
See: https://support.checkpoint.com/results/sk/sk34812
Otherwise, you should use a Dynamic Object in your NAT rule instead (which is what ISP Redundancy ultimately does).
You'll need to write a script to update the contents of this Dynamic Object using the dynamic_objects CLI command on each gateway that uses this object.
However, this gives you flexibility as to how and when to "fail over" the NAT.
Thank you..
If i configure two IP from different ISPs in a sigle dynamic object.Does NAT will failover to another IP automatically if one ISP fail ?
Configuring more than one IP in a Dynamic Object used in this manner won't fail over.
The script you write will determine the failover conditions and what IP is used in what case.
When you say make NAT rules for ISP redundancy, you mean create different nat rules based on what subnets would go out of which ISP link?
Or did I misunderstand that totally?
Andy
In this case, you don't need two rules, you only need one...in terms of the Dynamic Object you've created.
The Dynamic Object will determine what the IP will ultimately be translated to.
Never knew that was possible...would you mind attach a screenshot of what nat rule would look like in case like that?
Cheers,
Andy
The "translated source" would contain the Dynamic Object you created.
It's otherwise like any other NAT rule.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 10 | |
| 9 | |
| 8 | |
| 8 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY