Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ildar07
Explorer
Jump to solution

NAT Desination translate to network range

Hello, everybody.

Is it possible to create NAT rule, which in destination will be a range of IP addresses?

Example: some_network -> some_external_IP translate to some_network -> Range_IP. I  guess it is for some server balancing.

How it works on checkpoint - range or network objects in destination NAT? How checkpoint define which address will be used?

I need to know for Checkpoint R77.30 and last versions.

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

Range objects can be used in the NAT rulebase, but primarily in the Source field.
You can use them in the destination field if the NAT is STATIC (not HIDE) and the range is the exactly the same size as the source.

I don't believe you can use the NAT rulebase for load balancing.
However, we have a specific object type for this purpose (Logical Server).
See: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SecurityManagement_AdminGuid... 
See also: https://support.checkpoint.com/results/sk/sk31162 

View solution in original post

(1)
2 Replies
PhoneBoy
Admin
Admin

Range objects can be used in the NAT rulebase, but primarily in the Source field.
You can use them in the destination field if the NAT is STATIC (not HIDE) and the range is the exactly the same size as the source.

I don't believe you can use the NAT rulebase for load balancing.
However, we have a specific object type for this purpose (Logical Server).
See: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SecurityManagement_AdminGuid... 
See also: https://support.checkpoint.com/results/sk/sk31162 

(1)
the_rock
Legend
Legend

Yes, it is possible, I did that before.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events