- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi!
I don't understand why/how the following scenario works.
SMS is R81.10, Gateway is R80.40
I can set a Static NAT IP for a network object and can successfully install policy.
eg. setting STATIC NAT IP 10.0.113.2 on the network A-INT_NET (192.168.11.0/24)
In NAT rulebase - rule no 10 appears
Traffic to outside works for 2 hosts on that network. (I also have a second hide NAT that's made in pfsense above the lab environment)
Even weirder is that CKP logs shows succesful Source NAT, but not with .2 as in the rule, but with .204 which I don't even know where it appeared from. The Gateway's IP is 10.0.113.1
The virtual router above CKP lab doesn't have DHCP server active so that .204 IP couldn't have come from that.
Setting a static NAT on a network object does work, but almost certainly not the way expected. What you have done is NATed the entire 192.168.11.0/24 network to the entire 10.0.113.0/24 network. So traffic coming from 192.168.11.111 will be NATted to 10.0.113.111, 192.168.11.17 will be NATted to 10.0.113.17, etc. I think Cisco used to call this "LAN-to-LAN NATting", and this type of NAT operation just swaps out the network portion of the IP address (first three octets with a /24) and leaves the host portion (last octet) intact.
I believe the IPs in translated subnet are chosen randomly, so say if source is x.x.x.222, then dst might be y.y.y.252.
Interestingly, if you specify a range instead of a network, then it gets translated like for like.
Thats right, exactly how it works on Cisco.
I have been using static network to network NAT with VPNs for years, it works exactly as expected. For example: orig_src:10.23.0.0/16 xlate_src:192.168.0.0/16 will NAT the 3rd and 4th octet one to one. Where is this documented within Check Point's admin guides? Is there an sk?
Thanks.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY