- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I am trying to configure a policy to allow inbound access from the Internet to an internal server. I can create a NAT for the server so that the server is known by a public IP Address, but I have a problem with the return traffic.
I need to translate the public Source IP address of the connection to a internal IP address. So a "Hide NAT" for inbound connections.
Is this possible? As I am failing to find any instructions for configuring this.
We are running R80.10 on management and security gateways.
Many thanks,
Michael
Of course it is.
The main issue is that the "Source" for the rule can't be "Any".
You also can't use negation in the NAT rulebase either.
To achieve the desired result, you'll need two rules:

The first rule ensures the internal networks are NOT translated when they connect to the IP address (in this case, AR70).
"Protected Networks" is a group I created with my internal networks.
The second rule says "anyone connecting to AR70 with appear as if it's coming from foo and going to e7".
"All_Internet" should be a preexisting object.
After you add the object to the Translated Source, you will need to need to right-click on it and change the NAT Method to Hide.
Of course it is.
The main issue is that the "Source" for the rule can't be "Any".
You also can't use negation in the NAT rulebase either.
To achieve the desired result, you'll need two rules:

The first rule ensures the internal networks are NOT translated when they connect to the IP address (in this case, AR70).
"Protected Networks" is a group I created with my internal networks.
The second rule says "anyone connecting to AR70 with appear as if it's coming from foo and going to e7".
"All_Internet" should be a preexisting object.
After you add the object to the Translated Source, you will need to need to right-click on it and change the NAT Method to Hide.
HI,
Thanks for this confirmation. With the All_Internet object (which just seems to be another way of saying any) I got it working, My main block point was not knowing that I had to right click on the "Translated source" in the NAT policy to change it from a Static NAT to a Hide NAT.
Many thanks,
Michael
Awesome!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY