- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Everyone!
Currently we are facing a rather confusing problem as follows:
1. We have 1 pair of Checkpoint devices and 2 pairs of other vendor's Fw devices connected as shown in the attached image.
2. We use a host with IP 10.0.33.100 located behind the Checkpoint device to access the service on Fw1, traffic goes through a Switch device in the middle. Then we are login to Fw1 device and check the logs on Fw1, we can see source IP 10.0.33.100 connected.
3. We use hosting with IP 10.0.33.100 located behind the Checkpoint device to access the service on Fw2, traffic goes through two Switch devices in the middle. Then we log in to the Fw2 device and check the log on Fw2, we can only see the source IP is Checkpoint's administrative IP, in addition we cannot find any other source IP.
Has anyone had any problems?
If you have exact source and dst IP, have you tred running fw monitor to see what happens with the traffic?
Best,
Andy
also, if say dst is 1.1.1.1 (just replace with right IP), run ip r g 1.1.1.1 from expert mode to see if its taking the correct route.
Andy
Traffic when passing through the checkpoint we checked to see that it was on the right route. On the checkpoint we can clearly see the source and dst.
However, as I mentioned, when traffic from a host located behind the checkpoint accesses a host located behind device fw1 through 1 Switch device as shown in the picture I attached, then when we log in to device fw1 and check, we can easily see source is the IP of the host behind the Checkpoint.
However, when traffic from a host located behind the checkpoint accesses a host located behind the fw2 device through 2 Switch device as shown in the picture I attached, then when we log in to the fw2 device and check, we Only seeing the source is the administrative IP of the checkpoint update.
Sorry, I cant see the attachment...can you paste the diagram?
K, I see it now, ty. Just to make sure, these are 2 single firewalls managede by the same mgmt server?
Best,
Andy
We only have 1 pair of checkpoints configured in Cluster with separate management components.
And fw1 and fw2 are two pairs of firewalls from another vendor.
Currently, when logging into the fw2 device to check the logs, we cannot see the exact source IP of the host behind the Checkpoint device. When done, use that host to access the services behind fw2.
We can only see the VIP IP MGMT of the Checkpoint device.
K, so its a cluster, got it. Does same issue happen regardless of which fw is the active one?
Andy
The Cluster Checkpoint device run on mode active/active
Did you run zdebug to see if anything is dropped?
From your description it sounds like when you access fw1 the checkpoint don't perform source nat, but when you go to fw2 checkpoint do source nat.
Did you check the logs on checkpoint for traffic to fw2 and see if indeed you have xlate src and what nat rule does it match?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 23 | |
| 15 | |
| 14 | |
| 12 | |
| 10 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY