- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I am looking at the new options of the R82 version on NAT configuration for the Management Server and Gateway:
- On the SMS side, we can configure de NAT for using just the server original address or the translated address. (the default is to use one of both depending on the topology. This was the only option before R82)
- On the GW side, there is an option to override the configuration made on the SMS side.
I am having a hard time to find it out the utility of those new features. There is something similar in VPN link selection, but it is very clear that you override link selection to allow a gateway to use different interfaces in different VPN communities.
In the case of NAT, I only understand one new option: "Do no Create Automatic NAT rules". (The Security Management Server is behind a non-Check Point device that handles the NAT.)
But, I don't see why I would need to use one of the other new options. Usually I make an automatic static NAT so the GW can communicate with the SMS (by using "apply to Security Gateway Control Connections").
If somebody has an idea, I would be happy to look at it .
Thanks and have a nice weekend
Miguel Paton de Escalada (CCSE)
The new options give more control for complex situations. For example, they can help if you have multiple firewalls within a datacenter which you want to connect to the management via its private address, then firewalls in other facilities which you want to connect to it over the Internet.
The new options give more control for complex situations. For example, they can help if you have multiple firewalls within a datacenter which you want to connect to the management via its private address, then firewalls in other facilities which you want to connect to it over the Internet.
What @Bob_Zimmerman makes total logical sense.
Thank you Bob
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY