- Products
- Learn
- Local User Groups
- Partners
- More
Call For Papers
Your Expertise, Our Stage
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
Hi All,
I am very new to Checkpoint Firewall, We are using R77.30.
We want to make our server accessible publicly by using Public IP.This public IP is having GW different than the current one which is configured on fw for internet access.
I have tried making a Node with Static NAT, and allowed the traffic by making rules.
but when i use that internet stops working on the server. and its not working.
Please suggest.
Thanks,
Prashant.
In very simple terms what you want to do is have the ISP ROUTE your NEW IP Range to the Firewall on the Firewalls Current IP.
You can then create a Node for the Windows Server with the Private IP and then under Static NAT have the Public IP that want it known as.
At the moment when you do that then because the ISP Router has a Local Subnet for your Public IP then it does an ARP who has for the IP.
Nothing responds as doesn't exist and so you never get a reply.
If you provide the Check Point's External IP to your ISP and have them route the new Public IP Range to that IP then that will have the ISP Router forward all traffic for your new IP Range to the Check Point.
Hi,
Thanks for your reply. Please find attached config ss.
we have created one NAT rule hiding the server ip behind static public ip.
The problem is current public IP used for external traffic and the public ip we are going to use now have different GW.
Thanks,
Prashant.
Hi,
Our current network runs on following Public IP range.
NW: xxx.xxx.23.88/29
GW xxx.xxx.23.89
The new ip we got from ISP is this :
NW: xxx.xxx.6.72
GW : xxx.xxx.6.73
MASK: 255.255.255.248
The IP for server which we want to access publicly is 10.38.28.19
My concern is how can i flow traffic from servers IP to xxx.xxx.6.72 IP and vice versa.
Thanks,
What's the routing for the new network, where is the ISP routing it towards?
In very simple terms what you want to do is have the ISP ROUTE your NEW IP Range to the Firewall on the Firewalls Current IP.
You can then create a Node for the Windows Server with the Private IP and then under Static NAT have the Public IP that want it known as.
At the moment when you do that then because the ISP Router has a Local Subnet for your Public IP then it does an ARP who has for the IP.
Nothing responds as doesn't exist and so you never get a reply.
If you provide the Check Point's External IP to your ISP and have them route the new Public IP Range to that IP then that will have the ISP Router forward all traffic for your new IP Range to the Check Point.
Unfortunately not unless you are using Dynamic routing with your ISP?
Correct routing is a prerequisite for NAT.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 35 | |
| 22 | |
| 17 | |
| 12 | |
| 9 | |
| 9 | |
| 8 | |
| 8 | |
| 8 | |
| 7 |
Tue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY