Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RobertZdunek2
Explorer

Hairpin NAT alternatives

Hi CheckMates,

We've successfully deployed hairpin NAT described here: sk110019 - How to configure NAT Loopback (Hairpin NAT / NAT Reflection) on Check Point Security Gate... in our production environment. Works well, but the main disadvantage of that solution is that the server does not know who talks to it, as all traffic is translated to some gateway interface. Is there any other solution for LAN devices to talk to server over Public IP, that would keep source original IP, so the logs on the server shows who is really communicating?

 

Thanks,

Robert

0 Kudos
1 Reply
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

It becomes a networking problem. If the gateway isn't in path to de-NAT the reply packets, the client doesn't know why it's receiving those packets. If the C2S connection isn't NAT'd to the gateway IP, the reply packet won't get to the gateway to deNAT it. The best solution is to not have to NAT it at all, perhaps through name resolution or another mechanism.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 07 May 2026 @ 01:30 PM (AEST)

    CheckMates Live Sydney

    Tue 02 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Aarhus

    Wed 03 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Copenhagen
    CheckMates Events