- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
How to use multiple WAN ip addresses given ISP.
I want to set PAT, without using static NAT.
In other words, I want to configure Manual NAT for several public addresses on multiple lan hosts and dozen services.
If you are trying to "multiplex" a number of target hosts or servers behind each of the public IPs you are given, you may have to resort to Manual Proxy ARP configuration on your gateway or cluster and then create a number of NAT rules reflecting each inbound path and translation.
I also think that for each group of target hosts using same public IP, you should create a "Summary NAT" rule for return traffic with "Hide Behind" that public IP.
If, on the other hand, you simply have multiple public IPs and each one correlates to a single host on private IP range behind gateway, simply use Static NAT in the properties of each object representing servers and create access rules pointing services to them.
Regards,
Vladimir
You need to create a number of manual NAT rules above the Automatic rules like this:
When you do this above the automatic rules you can set the last internal with an automatic NAT as that will make sure the proxy ARP is also set.
From R80.20 proxy-ARP is also set for manual NAT rules but before that you needed to add them amnually on the gateway.
When you added the NAT rules and pushed them you can double check if the proxy ARP's are all set by typing 'fw ctl arp' on the gateway in cli.
Network diagram is here.
You need to create a number of manual NAT rules above the Automatic rules like this:
When you do this above the automatic rules you can set the last internal with an automatic NAT as that will make sure the proxy ARP is also set.
From R80.20 proxy-ARP is also set for manual NAT rules but before that you needed to add them amnually on the gateway.
When you added the NAT rules and pushed them you can double check if the proxy ARP's are all set by typing 'fw ctl arp' on the gateway in cli.
If you are trying to "multiplex" a number of target hosts or servers behind each of the public IPs you are given, you may have to resort to Manual Proxy ARP configuration on your gateway or cluster and then create a number of NAT rules reflecting each inbound path and translation.
I also think that for each group of target hosts using same public IP, you should create a "Summary NAT" rule for return traffic with "Hide Behind" that public IP.
If, on the other hand, you simply have multiple public IPs and each one correlates to a single host on private IP range behind gateway, simply use Static NAT in the properties of each object representing servers and create access rules pointing services to them.
Regards,
Vladimir
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY