- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters
E1: How AI is Reshaping Our World
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
After setting up NAT snmp translation, traffic goes only one way, there are no answers from the router, while on the router we see its response.
Do you see the return traffic in a packet capture on the Firewall?
how can we check it?
Using one of the following tools from the CLI:
Also what service object is used in your rule both to allow the traffic and for the NAT?
Please check the routing is symmetric or that there are no ACLs on the router impacting the traffic.
Both objects are used in the NAT policy?
routing is symmetrical, both objects are in NAT, no ACLs
Maybe an ARP issue?
If you use source NAT (not clear from your post if its source or destination NAT), then there are cases where you have to take care of ARP.
This is what I mean:
Simple Topology:
whatever is behind the router <- ROUTER eth2 (10.0.0.1) <- eth1 (10.0.0.254) GATEWAY eth 2 (172.16.0.1) <- Client (172.16.0.20)
Example 1:
You set a source NAT with translating 172.16.0.20 to 10.0.0.254. This will work out of the box.
Example 2:
You set a source NAT with translating 172.16.0.20 to 10.0.0.200. This will only work, if you setup 10.0.0.200 as proxy arp address in GAIA for that interface or activated the automatic proxy arp feature. Or you put a static arp entry in your routers ARP table (not recommended). Or you set a route on your router routing 10.0.0.200/32 to 10.0.0.254 (unusual).
Example 3:
You set a source NAT with translating 172.16.0.20 to 5.5.5.5. This will only work, if you set a route on your router routing 5.5.5.5/32 to 10.0.0.254.
Need to investigate why the traffic doesn't reach the gateway, depending on your NAT configuration it might be proxy-ARP issue or a problem elsewhere.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY