- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters
E1: How AI is Reshaping Our World
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I want to make Nat Rule for redundancy ISP for out going traffic. I have 2 ISP and Objects are Statically nated with their respective IP from ISP.I want configure a fail over nat rule. Is it possible or any other solution will be help full.
* ISPs are terminated in a Cisco Wan Switch and Checkpoint is connected directly with Wan Switch.
GW version 81.20
Is it a single ISP or the same ISP with two different NAT numbers?
If they are different ISPs, you should be able to accomplish this via ISP Redundancy.
See: https://support.checkpoint.com/results/sk/sk34812
Otherwise, you should use a Dynamic Object in your NAT rule instead (which is what ISP Redundancy ultimately does).
You'll need to write a script to update the contents of this Dynamic Object using the dynamic_objects CLI command on each gateway that uses this object.
However, this gives you flexibility as to how and when to "fail over" the NAT.
Is it a single ISP or the same ISP with two different NAT numbers?
If they are different ISPs, you should be able to accomplish this via ISP Redundancy.
See: https://support.checkpoint.com/results/sk/sk34812
Otherwise, you should use a Dynamic Object in your NAT rule instead (which is what ISP Redundancy ultimately does).
You'll need to write a script to update the contents of this Dynamic Object using the dynamic_objects CLI command on each gateway that uses this object.
However, this gives you flexibility as to how and when to "fail over" the NAT.
Thank you..
If i configure two IP from different ISPs in a sigle dynamic object.Does NAT will failover to another IP automatically if one ISP fail ?
Configuring more than one IP in a Dynamic Object used in this manner won't fail over.
The script you write will determine the failover conditions and what IP is used in what case.
When you say make NAT rules for ISP redundancy, you mean create different nat rules based on what subnets would go out of which ISP link?
Or did I misunderstand that totally?
Andy
In this case, you don't need two rules, you only need one...in terms of the Dynamic Object you've created.
The Dynamic Object will determine what the IP will ultimately be translated to.
Never knew that was possible...would you mind attach a screenshot of what nat rule would look like in case like that?
Cheers,
Andy
The "translated source" would contain the Dynamic Object you created.
It's otherwise like any other NAT rule.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 9 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY