- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I want to make Nat Rule for redundancy ISP for out going traffic. I have 2 ISP and Objects are Statically nated with their respective IP from ISP.I want configure a fail over nat rule. Is it possible or any other solution will be help full.
* ISPs are terminated in a Cisco Wan Switch and Checkpoint is connected directly with Wan Switch.
GW version 81.20
Is it a single ISP or the same ISP with two different NAT numbers?
If they are different ISPs, you should be able to accomplish this via ISP Redundancy.
See: https://support.checkpoint.com/results/sk/sk34812
Otherwise, you should use a Dynamic Object in your NAT rule instead (which is what ISP Redundancy ultimately does).
You'll need to write a script to update the contents of this Dynamic Object using the dynamic_objects CLI command on each gateway that uses this object.
However, this gives you flexibility as to how and when to "fail over" the NAT.
Is it a single ISP or the same ISP with two different NAT numbers?
If they are different ISPs, you should be able to accomplish this via ISP Redundancy.
See: https://support.checkpoint.com/results/sk/sk34812
Otherwise, you should use a Dynamic Object in your NAT rule instead (which is what ISP Redundancy ultimately does).
You'll need to write a script to update the contents of this Dynamic Object using the dynamic_objects CLI command on each gateway that uses this object.
However, this gives you flexibility as to how and when to "fail over" the NAT.
Thank you..
If i configure two IP from different ISPs in a sigle dynamic object.Does NAT will failover to another IP automatically if one ISP fail ?
Configuring more than one IP in a Dynamic Object used in this manner won't fail over.
The script you write will determine the failover conditions and what IP is used in what case.
When you say make NAT rules for ISP redundancy, you mean create different nat rules based on what subnets would go out of which ISP link?
Or did I misunderstand that totally?
Andy
In this case, you don't need two rules, you only need one...in terms of the Dynamic Object you've created.
The Dynamic Object will determine what the IP will ultimately be translated to.
Never knew that was possible...would you mind attach a screenshot of what nat rule would look like in case like that?
Cheers,
Andy
The "translated source" would contain the Dynamic Object you created.
It's otherwise like any other NAT rule.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 31 | |
| 18 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY