- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hell,
Let me first start off by making it known that I am not a Network guy buy far. I am more Infrastructure but do dabble and have some skill in quite a few areas. The more you know the better, right? lol.
So here is the scenario, I have Residential internet from AT&T, 1 Dynamic IP and a set of 5 Static IPs behind that, the modem/router is in IP Passthrough mode. I recently migrated from my Palo Alto PA-3050 where this setup "Just Worked". I now have 2 Checkpoint 5800's running Gaia R80.40 in a cluster and cannot for the life of me seem to get things back the way they were.
First attempt, give each Security Gateway a dynamic Internal IP from the modem/router on the 192.168.1.X/24 network. Configure the VIP and then select Gateway 1 to forward the traffic to from the modem/router. This works and i get internet, but can only use the Public Dynamic IP, cant use any of the static IPs behind that.
Second attempt, give each Security Gateway a Public IP, assign the Cluster VIP. This does not work, i dont get internet at all.
Third attempt, forward the traffic to Gateway 1, allow it to receive the Public Dynamic IP. Cant create the Cluster VIP as not both Gateways are in the same subnet, thus no internet.
Has anyone ever successfully configure a Checkpoint cluster behind a residential AT&T router/modem? Am I doing something wrong? I am missing something? Any help or guidance is greatly appreciated.
R80.40 is End of Support, FYI.
You may have to use NAT to use the static IPs.
Yes, I know it is EoS, I just need to hold off for a few more weeks until I receive my SMS then I can upgrade all to R82. I had to downgrade them to R80.40 due to the current SMS which is a bit older and only supports up to R80.40. Can you provide an example of a good working NAT, theoretically that is? I have tried a few different NAT scenarios and none seem to yield the required result. At the end of the day i just need to be able to use the Static IPs as a lot of my services are pointed to them.
What kind of nat did you try? hide or static?
I have tried both Hide and Static with no luck. Although, I will say that it is completely possible that the NAT rule wasn't setup correctly to begin with. I pretty much got lost with trying to translate Original and Translated with the Dynamic IP and one of the Static IPs, along with using Hide and Static.
Just try hide nat, hide behind att's router.
Im assuming this is where that change would be made??
Yup.
UPDATE - After some more tinkering I have come to believe its a Checkpoint thing, whether a missed setting or misconfiguration. I assigned the Gateways Static IPs, configured the cluster, installed Policy and now the only IP that works is the statically assigned IP to gateway #1. I tried with IP Passthrough both on and off and got the same result. Are there any good Youtube videos out there that would cover the cluster configuration?
Please provide screenshots of the exact configurations you've made here (hide the sensitive details).
You might also want to check that those IPs are being routed to the active gateway from the AT&T router by checking with tcpdump.
Nothing has changed on the AT&T side, previously with my Palo Alto, this just worked. I just configured one of the interfaces for DHCP and it received the IP. I was then able to use the Dynamic IP and the Static IPs behind that with no issue. Im sure Checkpoint does things a bit different than Palo Alto, thus my predicament. Just not sure what Im missing or misconfigured.
You tried doing nat on the object, right?
Well, I have now. Seems to have cleared the issue on some objects but not all. So it seems that I am just not familiar enough with Checkpoint. Thank you for the info and responses, truly appreciated.
Top info!
Yea, there are lots of great videos on that topic online.
 
					
				
				
			
		
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count | 
|---|---|
| 28 | |
| 16 | |
| 16 | |
| 14 | |
| 9 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | 
Wed 05 Nov 2025 @ 11:00 AM (EST)
TechTalk: Access Control and Threat Prevention Best PracticesThu 06 Nov 2025 @ 10:00 AM (CET)
CheckMates Live BeLux: Get to Know Veriti – What It Is, What It Does, and Why It MattersTue 11 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERTue 11 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY