- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Hi folks,
I want to get all host and network objects with enabled NAT.
The "Object Explorer" seems to be the best way to go for me.
But the NAT properties in the explorer overview and CSV export are different than the NAT setting of the object. The overview shows "None" and the object propertie shows "Hide" NAT enabled.
Do I missunderstood the explorer overview?
any other ideas how I can get all NAT enabled objects?
Thanks.
Jas Man
$MDS_FWDIR/scripts/web_api_show_package.sh -n 443 -cgrep and sort -u the CSV that contains your NAT policy or check and export the objects within your NAT policies with a browser plugin of your choice.$MDS_FWDIR/scripts/web_api_show_package.sh -n 443 -cgrep and sort -u the CSV that contains your NAT policy or check and export the objects within your NAT policies with a browser plugin of your choice.Sounds good.
Unfortunately the script causes a out of memory exception in Java.
JVMDUMP055I Processing dump event "systhrow", detail "java/lang/OutOfMemoryError", exception "Java heap space" at 2025/08/11 14:41:21 - please wait.
.......
Guess we've to activate the fix as descriped here: https://support.checkpoint.com/results/sk/sk119553
I'm right?
I dont believe so...check output from my mgmt.
Andy
[Expert@CP-MANAGEMENT:0]# $MDS_FWDIR/scripts/web_api_show_package.sh -n 443 -c
Script finished running successfully!
Result file location: show_package-2025-08-11_08-53-46.tar.gz
[Expert@CP-MANAGEMENT:0]#
I would expect the same output on our server. But as I've written, the script crashes with a OutOfMemoryError exception after some minutes.
The error takes me to https://support.checkpoint.com/results/sk/sk171173 and https://support.checkpoint.com/results/sk/sk119553.
I'm wrong with the implementation from SK119553 to solve the exception? Any recommendations or concerns?
I cant sadly even open thise SKs, cause its telling me technical issues when I try to log in. Since its mgmt server, just try cprestart or quick reboot.
Andy
Was just able to open the sk you referenced. Not sure it would apply to you, as it does not go past R80.40 and you are on R81.20, but maybe you can verify with TAC. Honestly, if I were you, I would simply reboot the mgmt server.
Andy
Restart done, but still the same error 😞
I've to ask our partner to solve this issue first. Thanks to all for your support.
I would definitely also open TAC case to check on this. To me, its certainly strange you get those errors, because such a script should run without any issues. Can you please confirm api status shows successful?
Andy
We're still struggeling with the error, but TAC provided us a workaround to export the needed data
mgmt_cli -r true show networks limit 500 offset 0 details-level "full" --format json >> FWMGNT_Export_Objects_1.json
mgmt_cli -r true show networks limit 500 offset 501 details-level "full" --format json >> FWMGNT_Export_Objects_2.json
mgmt_cli -r true show networks limit 500 offset 1001 details-level "full" --format json >> FWMGNT_Export_Objects_3.json
The export is limited to 500 objects. Therefore, we had to run it several times to get all objects. I've merged the files in PowerShell and exportet the needed fields.
Example I got. Happy to attach .tgz file for you, its my lab anyway, so nothing secretive. let me know.
Andy
| No. | Name | Original Source | Original Destination | Original Services | Translated Source | Translated Destination | Translated Services | Install-On | Comments |
|---|---|---|---|---|---|---|---|---|---|
| Automatic Generated Rules : Machine Static NAT (No Rules) | |||||||||
| Automatic Generated Rules : Machine Hide NAT (No Rules) | |||||||||
| Automatic Generated Rules : Address Range Static NAT (No Rules) | |||||||||
| Automatic Generated Rules : Network Static NAT (No Rules) | |||||||||
| Automatic Generated Rules : Address Range Hide NAT (No Rules) | |||||||||
| Automatic Generated Rules : Network Hide NAT (1-2) | |||||||||
| 1 | Automatic Rule: CP_default_Office_Mode_addresses_pool |
Any
|
|||||||
| 2 | Automatic Rule: CP_default_Office_Mode_addresses_pool |
Any
|
Any
|
||||||
| Manual Lower Rules (No Rules) | |||||||||
Never tried personally the way @Danny mentioned, but definitely makes sense.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 67 | |
| 42 | |
| 26 | |
| 14 | |
| 13 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 8 |
Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY