- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi. Im trying to redirect traffic going out a gateway. I want to change the traffic flow from:
host_a (port 443) -> checkpoint_gateway -> internet -> public ip on host_b
to:
host_a (port 443) -> checkpoint_gateway -> nat from public ip on host_b to private ip on host_b -> s2s ipsec tunnel -> private ip on host_b
The tunnel works fine for normal traffic flow over the tunnel and all the security domains are defined properly. There are rules in the policy that the traffic should hit to go over the tunnel. When I try to create a nat rule to change the public ip to the private ip of host_b the traffic is allowed and I see the translation but It doesnt get encrypted. Its also skipping my tunnel rule and hitting my default outbound rule at the bottom. What am I missing in my nat rule to get this traffic flow working?
There's an option to disable NAT in the VPN Community--see if that's set.
I just tested with one host behind the gateway. So the nat rule looks like this:
original source - test_host
original destination - public ip on host_b
original services - any
translated source - original
translated destination - private ip on host_b
translated services - original
install on - checkpoint_gateway
I see the traffic getting encrypted but the nat isnt getting applied. Anything else im missing?
There's an option to disable NAT in the VPN Community--see if that's set.
has the issue resolved after doing this changes?
Yes, as it clearly indicated by the Solution marked on the recommendation.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY