- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello CheckMates,
we had a bunch of 1500 appliances connected to the internet via LTE. Everything is working fine, VPN tunnels are up and traffic flows. But all appliances are shown as disconnected in Smartconsole/SmartviewMonitor. After debug we could see the LTE provider did some NAT for the appliance. The Managementserver does not get the real IP of the appliance, only the NATed IP. I think this is normal behaviour if any NAT is done on the way between remote and central gateway but do we have any chance to get a green state in Smartconsole for the LTE appliances with dynamic IPs?
Review the following articles sk120136 / sk93566 as a start, not all implied rules apply for traffic from DAIP gateways ...
@Chris_Atkinson checked these sarticles, everything looks fine. SmartProvisioning is mentioned in the article but we don't use this feature, alle gateways are defined as normal DAIP gateways. There are no firewall-rules between remote and central gateway.
Can you please explain the needed traffic flow for the "connect" state. Will be there a need for a cpd_amon connection from the management to the remote DAIP gateway or vice versa?
Please explain the NAT used here - sounds like static NAT, not dynamic IP to me...
@G_W_Albrecht we have no information which kind of NAT is done via the LTE provider, this is something mysterious done by the German Telekom in the LTE network. We could see the appliance getting IP-adress (10.xx.xx.xx) but on the management we could see the appliance as 80.xx.xx.xx.
Then maybe you can just be glad that VPN is working 8)
Central gateway has rules in-place of the implied rules for the traffic from DAIP gateway/s or is mgmt traffic via VPN?
Yes, rules exists for the management ports like cpd, fw_log, cpd_amon etc. VPN is working fine, logs are sent to the management. Only the state of the appliance is not shown as connected and the state of the VPN tunnel is shown as down in SmartviewMonitor.
Are there any requirements if the appliance will be installed behind another NAT-device ?
@Chris_Atkinson my question again.... we had a DAIP appliance behind a NAT device, only NAT no firewall. Will it be possible to get these appliance to the green state meaning "connected" in Smartconsole view ?
I've sought some feedback on your behalf (in the absence of a corresponding SK etc) and will update you accordingly.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY