- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi team,
I got an interesting task what I need to deploy.
I need to create a contitional NAT rule:
This is not a trivilal ISP redundancy setup, don't mix it. Both traffic should use the same ETH interface when leaving the gateway.
I welcome all ideas.
Akos
You could use a station which monitors IP A, and if not reachable, starts an automation using the Management API to change the NAT translated sourced in the NAT rule identified by UID. This change is reverted via another automation when IP A is reachable again.
Hi Alex,
Sounds great, but a policy install will be necessary, right? I will think about it.
Akos
Yes it would require a policy install. Alternately, you could always have the default NAT rule above your backup NAT rule, so that in case of reachability change you disable or enable the generally used NAT rule. Different object manipulation, depends on your policy setup.
At least with the API, you have full audit of what happened when. Also it gives you verification options which could be trickier with a shenanigans-based approach.
Instead, try to use zone into nat rules
I agree with that 100% @CheckPointerXL
I second @Alex- 's idea, just couple of notes:
1. If firewall from which you want to check IP_A is managed from the same management, you can use management to connect to firewall over SIC (cprid_util). If return value of ping is 0, IP_A is reachable, otherwise not reachable.
2. Create both NAT rules manually and save both NAT rule UIDs. One of NAT rule will be always disabled, second NAT rule will be always enabled. Depending if IP_A is reachable or not, first NAT rule with already known UID will be disabled, second NAT rule with already known UID will be enabled and vice versa.
3. script will be run on management every XY minutes and do needed action once change is detected, including policy push.
Hey brother,
Were you able to figure this out?
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY