- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have a Checkpoint Geo-Cluster in Active-Active Mode in AWS.. i need to setup outbound NAT for a webserver..WAN IP/Elastic IP of that server will be whitelisted at the remote site.
The issue here is i dont want to use NAT (hide behind Gateway) for outbound communication as in that case i have to share external ip of my GW.. i created a secondary IP in AWS for this Gateway and mapped an elastic ip with it..is there any way i can make Checkpoint take the secondary elastic IP while using hide behind Gateway NAT ? hide behind IP wont work here as its an Active-Active Cluster where one member handles traffic at a time..if i use hide behind ip ..outbound communication will fail if traffic switches to secondary device.
Pls advice..
You could try to use a Dynamic Object here, which is a sort of placeholder object.
This would go in the translated source of a manual NAT rule.
You would use the dynamic_objects CLI command on each gateway to set it to the correct value.
thanks for the reply.. i referred an article on Dynamic Objects which states to create Dynamic Objects and then define values by clicking on the Gateways and going in Dynamic Object section.. however, i cudnt find dynamic object tab when i double click on GWs.. i m using R80.40 Cluster.
Is this limited to other version ?
Dynamic Objects have existed for quite some time.
You create them here:
Think of it as a "placeholder" object you can use with the actual definition defined on the security gateway itself via the CLI.
More details here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Ok .. so i think i need to enable smartprovisioning before using Dynamic Objects.. is it a licensed feature ? license is required for Mgmt Server and all GWs it manages ?
SmartProvisioning generally requires a license.
However, they are not required for the use of Dynamic Objects.
Ok.. but how do i setup dynamic objects without smartprovisioning ? i am able to create dynamic objects fro mSmartconsole but i cudnt get to assigning values to created DO
The configuration for the values of the Dynamic Objects is done via the CLI as described in the SK I linked to.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY