- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Setup : External------------->[Checkpoint]-----------> DMZ
Configured a static NAT for a server hosted in DMZ . When trying to access the same from the external network, the traffic is reaching the External interface and going out via External interface itself instead of DMZ interface.
This is observed when a packet capture is done i, I, o, O all are observed on the same External interface [using fw monitor].
Any specific reason for this weird issue? anybody encountered the same issue?
Suggestions will be helpful.
Thanks in Advance...
In the SmartConsole NAT Global Properties is "translate destination on client side" unchecked for the type of NAT config (Automatic vs. Manual) you are using? If so you will need a static host-based route added to the firewall's routing table like this:
External NAT Address/32 -> Real Server DMZ address
In the SmartConsole NAT Global Properties is "translate destination on client side" unchecked for the type of NAT config (Automatic vs. Manual) you are using? If so you will need a static host-based route added to the firewall's routing table like this:
External NAT Address/32 -> Real Server DMZ address
If you don‘t see any NAT translated packet in the four states you followed Tim’s suggestions.
the packets comes in with an external address to an address address of the external interface. It is processed through all firewall states and after I is handled via the routing daemon. If no NAT occurs, it‘s routed back to the external address of the sending system.
You have To set the host route or enable translation on client site.
Please copy the output of the following command into the forum, then we can see what's going on.
# fw monitor -p all -e "accept(<your filter>);"
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY