- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
do you know how centrally managed the CP1430 behind a NAT router? I have nat-ed all the required ports from the Router Public IP to the Firewall. We have some isue on the VPN establishing (invalid ID Identifier).
How I should configure the gateway on the SMS?
172.16.0.1/24 -> CheckpointGateway -> 192.168.1.1/24 -> Router ->PublicIP ---> CheckPointGateway ---> SMS
I hope is clear.... I can establish a SIC and push policy correcly. I also receve the log on the SMS
Luigi
The gateway object IP on the SMS would be the public IP.
You said you configured NAT for the required ports--which ones specifically?
Also, when you try to either push policy, fetch policy, etc, what specific behavior do you see?
Error messages? Screen shots? Other information?
My environment is like the SK 101469 but the 1430 is Centrally Managed...
I assume you want a VPN to 3rd party VPN as explained here: sk108600: VPN Site-to-Site with 3rd party - maybe you should set the ID Type not to IP address but something else...
Nope, the both side are checkpoint gateways centrally managed
Please read sk108600 - maybe you should set the ID Type not to IP address but something else as i think it does send a wrong IP address... But you can analyze that using VPN Debug!
I have a similar setup but it fails on the SIC allready. In the SIC I see the LAN side IP adres in reverse notation and the match can't be made.
The hostname equals the object name in the policy for the Central firewall.
(SecurityPeer sent wrong DN: 1.255.168.192** Reset SIC from peer, and establish trust again. **)
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY