- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Morning.
We're trying to cut over from a cluster of 5000 series running R81.10 to a new cluster of 9000 series running R82 JHFA take 44. Management is running R82 take 44 as well and has been for several weeks now.
Within the NAT policy there are several NAT rules with "Gateways" in the install on column (screenshot attached). What seems to be happening is that when we flip over to the R82 gateway these NAT rules are not being matched and all Internal to Internal traffic is hitting the final manual NAT rule to hid behind the gateway public IP. It doesn't seem to be an issue when running on the old R81.10 gateway.
Where does this "Gateways" target come from and is it no longer supported on R82?
Thanks
So, it's confirmed that the "Gateways" installation target is not supported/enforced on R82 gateways. We change all the rules to use "Policy Targets" and this solved the issue.
Have you tried editing the "Gateways" object, what does it yield?
Unfortunately I cannot make out the object icon from the screenshot on my phone right now.
It's not editable at all. Double click or right-click edit is unavailable.
I've seen this on environments which were upgraded from R7X all the way to R81.XX. Seems like a dynamic objects representing the gateways, which doesn't exist anymore. So it's in the configuration but can not be edited, added and so on.
As the release notes state that R82 doesn't support R77.30 versions, it might not be enforced at all.
I suspected this might be the case. As far as I can tell from the history, this policy has been around since somewhere around the R65 days so what you're saying makes sense. We've got a change scheduled for later to change all those to "Policy Targets" and try again.
Thanks!
For sure...if its been around since R65 days, then all @Alex- said is 100% logical.
So, it's confirmed that the "Gateways" installation target is not supported/enforced on R82 gateways. We change all the rules to use "Policy Targets" and this solved the issue.
any official reference?
Really odd...I use gateways as install target in R82 lab, never any issues. Maybe someone else can confirm.
We didn't even have Gateways as an available option on new rules. Very odd.
I will check in the lab shortly, but Im 100% positive I had seen it there before and changed it few times.
Do you see below option?
Yes I have that, but those are explicitly defined Gateway objects. The one I'm referring to is kind of a dynamic object which I believe references any object defined as a gateway. It looks like this:
Ah, got it...my apologies then. That, sadly, cant find...what I pasted was all that came up. Let me keep checking.
Not much to check, this object can't be used anymore. It might be imported from long-standing configurations which were upgraded from version to version up to now, but that's about it. And as discussed, since R82, it stops being enforced altogether.
An honestly, "Policy targets" is way more explicit and understandable than just "Gateways".
You are 100% right Alex. I will triple check everything, but Im 99.99% sure it wont be there.
That's exactly the conclusion we came to. It just doesn't seem to be documented or reference anywhere that I can find.
In the meantime, we've added this to our list of things to watch out for when planning upgrades to R82+
I looked everywhere, no dice, so its safe to say its not there, for sure.
None that I can find, no.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 10 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY