- Products
- Learn
- Local User Groups
- Partners
- More
What's New in Check Point SASE
Wednesday, 9 September @ 5pm CET / 11am EDT
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Morning.
We're trying to cut over from a cluster of 5000 series running R81.10 to a new cluster of 9000 series running R82 JHFA take 44. Management is running R82 take 44 as well and has been for several weeks now.
Within the NAT policy there are several NAT rules with "Gateways" in the install on column (screenshot attached). What seems to be happening is that when we flip over to the R82 gateway these NAT rules are not being matched and all Internal to Internal traffic is hitting the final manual NAT rule to hid behind the gateway public IP. It doesn't seem to be an issue when running on the old R81.10 gateway.
Where does this "Gateways" target come from and is it no longer supported on R82?
Thanks
So, it's confirmed that the "Gateways" installation target is not supported/enforced on R82 gateways. We change all the rules to use "Policy Targets" and this solved the issue.
Have you tried editing the "Gateways" object, what does it yield?
Unfortunately I cannot make out the object icon from the screenshot on my phone right now.
It's not editable at all. Double click or right-click edit is unavailable.
I've seen this on environments which were upgraded from R7X all the way to R81.XX. Seems like a dynamic objects representing the gateways, which doesn't exist anymore. So it's in the configuration but can not be edited, added and so on.
As the release notes state that R82 doesn't support R77.30 versions, it might not be enforced at all.
I suspected this might be the case. As far as I can tell from the history, this policy has been around since somewhere around the R65 days so what you're saying makes sense. We've got a change scheduled for later to change all those to "Policy Targets" and try again.
Thanks!
For sure...if its been around since R65 days, then all @Alex- said is 100% logical.
So, it's confirmed that the "Gateways" installation target is not supported/enforced on R82 gateways. We change all the rules to use "Policy Targets" and this solved the issue.
any official reference?
Really odd...I use gateways as install target in R82 lab, never any issues. Maybe someone else can confirm.
We didn't even have Gateways as an available option on new rules. Very odd.
I will check in the lab shortly, but Im 100% positive I had seen it there before and changed it few times.
Do you see below option?
Yes I have that, but those are explicitly defined Gateway objects. The one I'm referring to is kind of a dynamic object which I believe references any object defined as a gateway. It looks like this:
Ah, got it...my apologies then. That, sadly, cant find...what I pasted was all that came up. Let me keep checking.
Not much to check, this object can't be used anymore. It might be imported from long-standing configurations which were upgraded from version to version up to now, but that's about it. And as discussed, since R82, it stops being enforced altogether.
An honestly, "Policy targets" is way more explicit and understandable than just "Gateways".
You are 100% right Alex. I will triple check everything, but Im 99.99% sure it wont be there.
That's exactly the conclusion we came to. It just doesn't seem to be documented or reference anywhere that I can find.
In the meantime, we've added this to our list of things to watch out for when planning upgrades to R82+
I looked everywhere, no dice, so its safe to say its not there, for sure.
None that I can find, no.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 10 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 |
Tue 08 Sep 2026 @ 10:00 AM (CEST)
Keeping Pace with AI-Powered Threats: A New Approach to Closing Security Gaps Faster - EMEATue 08 Sep 2026 @ 05:00 PM (CEST)
Keeping Pace with AI-Powered Threats: A New Approach to Closing Security Gaps Faster - AmericasWed 09 Sep 2026 @ 11:00 AM (EDT)
What's New in Check Point SASE: Extending Secure Connectivity to China and BeyondTue 08 Sep 2026 @ 10:00 AM (CEST)
Keeping Pace with AI-Powered Threats: A New Approach to Closing Security Gaps Faster - EMEATue 08 Sep 2026 @ 05:00 PM (CEST)
Keeping Pace with AI-Powered Threats: A New Approach to Closing Security Gaps Faster - AmericasThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsTue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY