- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi Checkmates,
I have a standalone box on VM, I'm trying to create a DNAT rule for servers that are directly connected to CP box.
#################
Firewall interfaces :
10.10.10.101 -eth0
20.20.20.101- eth2
#################
I have servers behind each of these interfaces, I'm trying to create a DNAT for the web server manually, Below are the steps that I followed.
1>Created a DNAT rule.
2>Created a proxy ARP entry in WebUI.
3>Enabled manual proxy in global config.
4>Installed policy.
Web server 10.10.10.10
Client - 20.20.20.10
##############
Below is the proxy arp o/p from cli
[Expert@CheckPoint_SA:0]# fw ctl arp
(20.20.20.105) at 00-0c-29-12-90-66
[Expert@CheckPoint_SA:0]# ifconfig eth2
eth2 Link encap:Ethernet HWaddr 00:0C:29:12:90:66
inet addr:20.20.20.101 Bcast:20.20.20.255 Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:2854 errors:0 dropped:0 overruns:0 frame:0
TX packets:180 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:265199 (258.9 KiB) TX bytes:10990 (10.7 KiB)
==========
I have attached screenshots for the NAT rule and the access rule .
Can someone please help me figure out what's happening here!
=========
WR,
FH
The proxy-arp mac should match the interface mac from the same subnet.
Yes the traffic must be accepted by the access policy (NAT IP).
If you used NAT on the object itself elements of the policy may appear different by comparison.
Is Linux_2 the client and Linux_1 the server?
Yes @Chris_Atkinson .
Can the client learn the arp, any drop logs?
If this is VMware is it configured per sk101214.
Hi @Chris_Atkinson ,
If you take a look at my proxy ARP output, the MAC of eth2 and the NAT IP are the same. Is this expected ?
Also I'm seeing drops for the traffic initiated to the NAT IP , it is matched by cleanup rule. I'm a little confused here, I have used the real IP in access control policy , can it be the reason.
=====
WR,
FH
The proxy-arp mac should match the interface mac from the same subnet.
Yes the traffic must be accepted by the access policy (NAT IP).
If you used NAT on the object itself elements of the policy may appear different by comparison.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 20 | |
| 16 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolFri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY