- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
I've been looking for SK to talk about how to configure a Hide NAT with specific Public IPs in ISP Redundancy. I mean how to can i create a outbound traffic with a Hide NAT pool (Specific IP for each ISP) not Gateway IP address.
I've been searching in history of GAIA OS from R76 to R80.30. I cannot see that this feature have been added.
For example:
Email Servers: When we have a this scenario to load balanced a SMTP traffic, always need to respond from the same source for inbound and outbound. When we have a ISP Redundancy, the concepts to configure a ISP Redundancy are:
- To have redundance of services in most cases SMTP Traffic inbound and outbound for each ISP Public.
I know that Check Point is not a Load Balancer but at least need to have this feature because the only outbound load balancer is the Gateway IP Address.
Any information or SK or future feature in R80.40 and above, please let me know i will appreciate it.
Regards,
Try this:
Static NAT fails for outgoing connections through gateway with ISP Redundancy in Load Sharing mode
It includes the use of dynamic objects to figure out which interface the connection goes through, but it should work...
Wing_Chow,
if you are using ISP redundancy in LoadSharing mode both ISP links are used for outgoing connections.
Regarding the hide NAT, the default behaviour is to hide NAT the connection behind the outgoing interface.
You must define an automatic hide NAT on the network- or host-object, select "hide behind gateway" and set your gateway with the ISP redundancy as install on target. You don't have to specify an IP-address in the NAT configuration.
And you can't use the automatic NAT-configuration on the gateway. Option "hide internal networks behind gateways" is not supported with ISP redundancy in LoadSharing mode.
With this configuration outgoing packets via ISP-A are hide NATed behind the interface of ISP-A and outgoing packets via ISP-B are hide NATed behind the interface of ISP-B.
Wolfgang
Try this:
Static NAT fails for outgoing connections through gateway with ISP Redundancy in Load Sharing mode
It includes the use of dynamic objects to figure out which interface the connection goes through, but it should work...
Hi Eli_Faskha,
I have Tested for inbound and outbound and working good.
Thanks a lot.
Regards,
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY