- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello everyone,
Have a interesting problem, I am missing something. Our configuration the Firewall R81.10. local managed. We have 2 Email Servers configured as a DAG, behind the Firewall and tried to NAT both to the same Public IP, the ending is .250, (Firewall has .251), When we send a email for example to ping@mxtoolbox, it shows that the email is coming from .251. When we go to browser on either of the Email Servers and make a speedtest it shows up with the correct .250 Address.
Obviously our problem is some Emails are refused since the .251 is no MX entry in the DNS. So how should we configure the NAT correctly?
Have added our NAT table DAG-Email contains both internal IP of Email Servers EX_NAT is public address .250 EX2019 and EX19-2 corresponds to the internal Email Servers.
All 3 NAT are clicked "Hide multiple sources behind the translated source addresses" as well as "Serve as an ARP Proxy for the original destination IP address".
BTW we have a 3rd Email Server using NAT with .253 that works fine.
Would greatly appreciate some help with this, I obviously am missing something.
Thanks much
JJY
Could you share a pic of the NAt rules? Simply blur out the sensitive data
I thought I had added the .png
Just to make sure there is no connection that "stuck" somewhere, have you tried rebooting the fw?
Andy
Thanks for support, but yes have rebooted a couple of times.
K, just to make sure we got this right, do you have basic diagram of what exactly is supposed to be natted and how? I think that way, we can 100% ensure its right.
Andy
Now I suggest you to do packet capture eg.: # fw monitor, and check what happening. Does the packet leave the CheckPoint, or stucks is somewhere, as Andy told.
A little help for the syntax : https://tcpdump101.com/
Maybe an fw ctl zdebug + drop | grep IP can be useful as well.
Akos
@AkosBakos Thank you for promoting my colleague's site, appreciated it mate! We gave it to few customers in the past when we would go on site to do work for them, I hope they still use it : - )
Andy
Really? One of the best sites ever 🙂
O yea, he is super nice guy. Funny enough, he actually gave me R60 CCSA and CCSE training back in 2009 (makes me feel old lol). Im sure @PhoneBoy knows him really well.
These days, he is really busy, so he may update the site from time to time, but probably not as often as he used to. but, if you or anyone else has a feedback, Im sure he would be more than happy to look into whatever suggestions people have.
Andy
We worked together for a hot minute, so yeah. 🙂
I still think simple diagram would help us, just blur out any sensitive data.
Andy
Hi Jeff,
K, so just to make sure I got this right (tx for the diagram btw, excellent), is it the case where 172.17 and .18 hosts are supposed to be natted to 88.x.x.x IPs respectively?
Andy
Hi Andy,
Yes, acutally quite strange, the 2 Exchange servers are in a Microsoft DAG so both Servers contain all Mailboxes and both Send/Recieve Emails. Both Servers 172.17.0.6/7 should be NATed to 88.217.xx.250. When using the browser (HTTPS), to identify ip Address it shows on both Servers correctly 88.217.xx.250. However when sending Emails, (to help identify problem, presently only the .6 is used to send Emails), in the header it shows Email is coming from the 88.217xx.251, which is the IP Address of the Checkpoint. This of course does not correspond to SPF,DMARC, and DKIM. Have presently helped simply by adding the .251 Address as a mx. But this will not work long since it is not possible to create a DKIM for the Firewall.
The Internet settings for both under NAT the 'Do not hide internal networks behind this Internet connection' is not clicked . If it is clicked then the correct ip Address is used in sending Emails, (in other words works as should), however all other Servers can no longer connect to the Internet.
Hope this description is understandable :).
Thanks again,
Jeff
It is, yes, thanks! Hey, if you allow remote, I would love to do it and see if we can figure this out. Im in EST, which is GMT-4 I believe, so its 7.30 am here, I can do around 8.30 am my time, if that works?
Let me know.
Andy
Hi Andy,
Sure, so about 1hr? can send me an email info@softwhere-it.com could give you direct access to FW or Remote up to you.
Greets,
Jeff
Are you free in about 15 mins? I can send you direct message here with zoom link if that works?
Andy
Yes, am available now, had to go to Mac's for some food, (if you can call it that!)
K, messaged you directly with zoom link
Andy
Hey Jeff,
I looked into this a bit more (set up quick demo lab) for smb and was wondering if you see the same option I attached, though this is R81.10.10 version. im almost positive you showed me is checked, but just wanted to confirm if same setting is there. Btw, another thing I thought of...since you said this works randomly, did you ever try disable/re-enable NAT rules or even delete/re-create them??
Andy
Also emailed you via my personal gmail.
Andy
Given the screenshots suggest this is on a Quantum Spark appliance, I've moved the message to the correct space.
What blades are enabled here?
While there are a few screens that will provide all the information in aggregate, the easiest thing to do is type the following in expert mode: enabled_blades.
Hey everyone,
Just finished zoom remote with Jeff. We verified NAT is 100% correct, as well as rules/mail server config. Weird thing is this works randomly, but mostly it does not.
Zdebug does not show anything, but fw monitor shows connection from mail server to the fw, but then nothing form the fw further.
Jeff will open TAC case for it and update us how it gets solved.
Thanks @again @Softwhere for your time, it was nice talking to you. Next time Im in Munich, we should go to Mac's for some "good" food 😂😂
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
5 | |
4 | |
3 | |
2 | |
2 | |
1 | |
1 | |
1 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY