- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
A query, I have a S2S IPsec VPN against a third party, in which, on our side we have the need that "the remote peer" does not know us with the real IPs of our servers.
These are our Real IPs:
10.7.12.124
10.7.106.114
192.168.216.50
Destination IP of the remote peer:
69.20.50.41
These 3 IPs, must "present" themselves to the remote peer, with the NAT IP -> 172.26.15.254
Checkpoint requires that in this case, 3 Hide NAT type rules are created for each of the real IPs, right?
It is not possible to work it in only one NAT rule?
Cheers. 🙂
Yes, it is possible to setup groups in the NAT rule base for your hide NAT. I use this feature quite often.
You can absolutely put those 3 servers into a group and specify hide behind 172.26.15.254 when talking to the other remote network.
Hey bro,
Make sure NAT is enabled inside vpn community and if its static nat rules, then they may need to be separate.
Andy
Buddy
The TAC told me that in order for Checkpoint, to take my manual NAT rules into account, I have to disable the checkbox of the option that you see in the following image. 😄
For now, my manual NAT works fine, but it is configured as a 1 - 1 NAT.
And what I want is that on my side, there are 3 servers with different IPs, that can reach the other side of the VPN, with a single NAT IP.
Is it possible to make a Hide NAT, using as origin a "group object" and putting there, all the IPs that I want to leave my side ????
Greetings.
Sorry, my bad, I believe TAC is correct. Also, as per below, makes sense
VPN Communities - Advanced (checkpoint.com)
Btw, if its hide NAT rule, then group should work.
Andy
Yes, it is possible to setup groups in the NAT rule base for your hide NAT. I use this feature quite often.
You can absolutely put those 3 servers into a group and specify hide behind 172.26.15.254 when talking to the other remote network.
100% that works, agree.
Andy
Thanks for the support, guys.
Cheers. 🙂
FYBFOC = for you bro, free of charge 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 28 | |
| 20 | |
| 15 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY