- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Below is my configuration of my lab :-
1. Mgmt PC - 172.16.31.22 (Vmnet 1)
2. Mgmt Server - 172.16.31.110 (Vmnet 1)
3. GW-1 - 172.16.31.1 (Vmnet 1) --------------------Internal network
4. GW-1 - 192.168.1.251 ( Bridged to WIFI network) ----------------outside network || Also enabled NAT on this interface. Nat IP - 192.168.1.251
5. GW-2 - 192.168.1.250 ( Bridged to WIFI network) ----------------outside network
--------------------------------------------------------------------------------------------------------
Default gateway of Mgmt PC and Mgmt Server is the IP address of GW-1 (172.16.31.1)
Policies installed : -
1. Mgmt Pc - GW-1 and GW-2 --------------Accept the traffic of https/http/icmp/dns.
2. Mgmt Server - GW-2 ------------------Accept all the traffic.
Now, when I add the gateway in Mgmt server, the status will turn into Green, but when I install the above policies - I got the message that connection is lost with GW-2 and when I checked the logs, it said that CPD traffic drop from GW-2 to GW-1 (port 18191).
Please provide the solution of my query.
Dear Team, Good Evening,
This is Victor here and I am new to this community. Even I am also facing the same issue for same scenario and setup on Vmware. I have two sites setup namely HQ and Branch. From a PC on HQ site I am trying to do an HTTPS connection for the Branch Firewall which is not working. I have configured Hide NAT for the HQ network , HTTPS service rule is also configured. Traffic for rule is also accepted but when I am checking the logs I can see The HQ FW is dropping the CPD 18191 traffic from the Branch FW to HQ FW due to the CleanUp rule but the Branch FW is accepting the same traffic due to the Implied rule.
FYI: Both sites are UP and running, no connectivity issues yet.
Kindly help or suggest if I am missing something or have wrongly configured things.
Kindly see the attachment pic for clarity of the issue.
Thanks.
NAT for management is generally recommended with Static NAT (not HIDE NAT).
It’s possible you will need an explicit rule to permit this communication.
Thanks a lot for the help, noted your point, will implement as suggested.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY