- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi folks,
I want to get all host and network objects with enabled NAT.
The "Object Explorer" seems to be the best way to go for me.
But the NAT properties in the explorer overview and CSV export are different than the NAT setting of the object. The overview shows "None" and the object propertie shows "Hide" NAT enabled.
Do I missunderstood the explorer overview?
any other ideas how I can get all NAT enabled objects?
Thanks.
Jas Man
$MDS_FWDIR/scripts/web_api_show_package.sh -n 443 -c
grep
and sort -u
the CSV that contains your NAT policy or check and export the objects within your NAT policies with a browser plugin of your choice.$MDS_FWDIR/scripts/web_api_show_package.sh -n 443 -c
grep
and sort -u
the CSV that contains your NAT policy or check and export the objects within your NAT policies with a browser plugin of your choice.Sounds good.
Unfortunately the script causes a out of memory exception in Java.
JVMDUMP055I Processing dump event "systhrow", detail "java/lang/OutOfMemoryError", exception "Java heap space" at 2025/08/11 14:41:21 - please wait.
.......
Guess we've to activate the fix as descriped here: https://support.checkpoint.com/results/sk/sk119553
I'm right?
I dont believe so...check output from my mgmt.
Andy
[Expert@CP-MANAGEMENT:0]# $MDS_FWDIR/scripts/web_api_show_package.sh -n 443 -c
Script finished running successfully!
Result file location: show_package-2025-08-11_08-53-46.tar.gz
[Expert@CP-MANAGEMENT:0]#
I would expect the same output on our server. But as I've written, the script crashes with a OutOfMemoryError exception after some minutes.
The error takes me to https://support.checkpoint.com/results/sk/sk171173 and https://support.checkpoint.com/results/sk/sk119553.
I'm wrong with the implementation from SK119553 to solve the exception? Any recommendations or concerns?
I cant sadly even open thise SKs, cause its telling me technical issues when I try to log in. Since its mgmt server, just try cprestart or quick reboot.
Andy
Was just able to open the sk you referenced. Not sure it would apply to you, as it does not go past R80.40 and you are on R81.20, but maybe you can verify with TAC. Honestly, if I were you, I would simply reboot the mgmt server.
Andy
Restart done, but still the same error 😞
I've to ask our partner to solve this issue first. Thanks to all for your support.
I would definitely also open TAC case to check on this. To me, its certainly strange you get those errors, because such a script should run without any issues. Can you please confirm api status shows successful?
Andy
We're still struggeling with the error, but TAC provided us a workaround to export the needed data
mgmt_cli -r true show networks limit 500 offset 0 details-level "full" --format json >> FWMGNT_Export_Objects_1.json
mgmt_cli -r true show networks limit 500 offset 501 details-level "full" --format json >> FWMGNT_Export_Objects_2.json
mgmt_cli -r true show networks limit 500 offset 1001 details-level "full" --format json >> FWMGNT_Export_Objects_3.json
The export is limited to 500 objects. Therefore, we had to run it several times to get all objects. I've merged the files in PowerShell and exportet the needed fields.
Example I got. Happy to attach .tgz file for you, its my lab anyway, so nothing secretive. let me know.
Andy
No. | Name | Original Source | Original Destination | Original Services | Translated Source | Translated Destination | Translated Services | Install-On | Comments |
---|---|---|---|---|---|---|---|---|---|
Automatic Generated Rules : Machine Static NAT (No Rules) | |||||||||
Automatic Generated Rules : Machine Hide NAT (No Rules) | |||||||||
Automatic Generated Rules : Address Range Static NAT (No Rules) | |||||||||
Automatic Generated Rules : Network Static NAT (No Rules) | |||||||||
Automatic Generated Rules : Address Range Hide NAT (No Rules) | |||||||||
Automatic Generated Rules : Network Hide NAT (1-2) | |||||||||
1 | Automatic Rule: CP_default_Office_Mode_addresses_pool |
Any
|
|||||||
2 | Automatic Rule: CP_default_Office_Mode_addresses_pool |
Any
|
Any
|
||||||
Manual Lower Rules (No Rules) |
Never tried personally the way @Danny mentioned, but definitely makes sense.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
30 | |
16 | |
4 | |
4 | |
4 | |
3 | |
3 | |
3 | |
3 | |
2 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY