- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I am configuring a Check Point firewall with two internet links in Load Sharing mode using ISP Redundancy. The NAT is set up on the internal network objects using the "Hide Behind Gateway"
I have the following questions:
How does NAT function in Load Sharing mode?
Does the firewall apply Hide NAT based on the active ISP interface for each connection?
Are static NAT rules ignored in this mode?
Is it possible to use a SNAT Pool with ISP Redundancy in Load Sharing mode?
Can I configure a pool of public IPs for outgoing connections, ensuring that traffic is NATed to the appropriate public IP based on the active ISP link?
This is what AI Copilot has to say for the matter:
Here are detailed answers to your questions about NAT and ISP Redundancy in Load Sharing mode on Check Point firewalls:
Summary Table
| Scenario | Supported? | Notes |
|---|---|---|
| Hide NAT per ISP | Yes | NATs to interface IP of egress ISP |
| Static NAT in Load Sharing | Yes | Required for incoming connections |
| SNAT Pool (native) | No | Workarounds possible with manual NAT and dynamic objects |
| Pool of public IPs per ISP | Possible (manual) | Requires advanced configuration and scripting (see SK174197) |
If you need step-by-step guidance for a specific advanced NAT pool scenario, let me know your exact requirements and I can provide more detailed instructions!
This is what AI Copilot has to say for the matter:
Here are detailed answers to your questions about NAT and ISP Redundancy in Load Sharing mode on Check Point firewalls:
Summary Table
| Scenario | Supported? | Notes |
|---|---|---|
| Hide NAT per ISP | Yes | NATs to interface IP of egress ISP |
| Static NAT in Load Sharing | Yes | Required for incoming connections |
| SNAT Pool (native) | No | Workarounds possible with manual NAT and dynamic objects |
| Pool of public IPs per ISP | Possible (manual) | Requires advanced configuration and scripting (see SK174197) |
If you need step-by-step guidance for a specific advanced NAT pool scenario, let me know your exact requirements and I can provide more detailed instructions!
On top, I would also add sk42636 and all other SKs referenced there.
Thank You @_Val_ !
I guess the best way is to implement SD-WAN in this case.
My customer has too many diferent rules with DIfferent Source IPs and wants to use both ISP links.
You got it, makes total sense.
Andy
With Quantum SD-WAN You can achieve all that in a much simpler way including using SNAT pool per ISP with load sharing per traffic (user/src/dst/updatable obj, application, etc)
Also Quantum SD-WAN will still accelerate those connections, in oppose to ISP Redundancy Load sharing that uses slow path AFAIK.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 16 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 4 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY