- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello, I need to disable NAT-T for a single S2S VPN, because if I disable it on the gateway object, the mobile blade does not work and remote users are affected. That means:
NAT-T enabled: Remote Users OK. - S2S VPN fails.
NAT-T disabled: Remote Users fail. - S2S VPN OK.
The VPN community settings does not allow to disable it for that particular community.
Is there something I'm missing? Thanks for the help.
You can't modify how NAT-T behaves at the VPN Community level, but you can do it at the object level and all this would apply for your gateways, externally managed gateways, and interoperable devices. So what you could try is modifying these GUIdbedit properties on the object representing the peer gateway on the other side of the tunnel, or you may be able to adjust these on your own gateway object without breaking RAS VPN, the last one in the list in particular. The default values for R81.20 are shown:
Drop UDP 4500 from the other peer IP. Only allow ESP and ike500.
NAT-t is most of the time started by the other side. In older versions Check Point only accepts and do not send.
Newer version depends on config (is global setting)
You can only as far as I know disable it on global level.
I think is allowed by implicit rules... if so, fw accel dos rule is needed, or also a fake nat rule it should work
You can't modify how NAT-T behaves at the VPN Community level, but you can do it at the object level and all this would apply for your gateways, externally managed gateways, and interoperable devices. So what you could try is modifying these GUIdbedit properties on the object representing the peer gateway on the other side of the tunnel, or you may be able to adjust these on your own gateway object without breaking RAS VPN, the last one in the list in particular. The default values for R81.20 are shown:
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 9 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY