- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello everyone,
I have a setup which is the following:
The ISP router is connected to another firewall (Fortigate) which routes traffic to the VIP (10.11.103.1).
My default route is 10.11.103.254 (which is the Fortigate private interface IP address), the internet access works perfectly.
My concern is to setup a Remote VPN access using the public IP address. Is Statically NATed IP address is the best option I have under Link Selection configuration ? (I have tried it but the VPN lient doesn't recognize the site ), or there is another option for me I can use to configure it?
Thank you in advance
Hello everyone,
Thank you so much for your suggestions and your feedback, and am sorry for my late response.
We managed to fix the issue. Indeed, the Fortigate guy didn't perform a Dnat to check point VIP, that's why it didn't work.
Once he perfomed it, the client VPN worked perfectly.
Thank you again for your assistance and your help.
Regards,
DAFIRI Omar
Link Selection to a static IP (the public NAT) is the correct configuration.
Have you done any packet captures to confirm the Fortinet box is forwarding all the relevant traffic to the Check Point gateway?
Sounds like you have the right config already. As phoneboy said, maybe do some packet captures to see what gives. Some examples below (lets just assume client IP is 1.2.3.4 and gw ip is 4.3.2.1)
On gateway (expert mode)
fw ctl zdebug + drop | grep 1.2.3.4
fw monitor -e "accept host(1.2.3.4) and host(4.3.2.1);"
fw monitor -e "accept port(18234);" (18234 is tunnel test port)
fw monitor -F "1.2.3.4,0,4,3,2,1,0,0" -F "4.3.2.1,0,1.2.3.4,0,0"
Idea in last command is this "srcIP,srcPort,dstIP,dstport,protocol" and then 2nd one is just other way around
Let us know what you get.
Hope those help.
Im fairly experienced in Foirtinet (though nothing like few of my colleagues lol), but you can also do packet capture there as well. I know in any 7.x.x version, its available via GUI, or just via cli:
diag sniffer packet any host x.x.x.x 4 50
This is in latest 7.4.0 version
Andy
Hello everyone,
Thank you so much for your suggestions and your feedback, and am sorry for my late response.
We managed to fix the issue. Indeed, the Fortigate guy didn't perform a Dnat to check point VIP, that's why it didn't work.
Once he perfomed it, the client VPN worked perfectly.
Thank you again for your assistance and your help.
Regards,
DAFIRI Omar
Excellent! 👍
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY