- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I have a strange case.
I have an access rule, created to consume a domain.
The rule is working by FQDN (domain object).
The traffic is intermittent, for port 444 (Sometimes the rule works, and sometimes not).
When the rule does not work, it is because in the logs, you can see that the traffic at that time, does not NAT, and therefore can not reach the Internet.
The rule has that sense:
SRC: 192.168.70.0/0, 192.168.170.0/24, 192.168.130.0/24
DST: Domain Object -> ".sunat.gob.pe"
Services: 80, 8080, 444
Action: Accepted
The traffic for the other services like 80, and 8080, work fine, but the "instability" is when they want to consume that destination through port 444.
Sometimes it works, and sometimes it does not.
Any idea how to solve this intermittence?
I share 1 file, which contains the moment, when the rule works correctly, and the moment when the rule does not work.
Thanks for your comments.
Make sure all options for NAT in global properties are checked.
Andy
Hello,
Do you mean this option?
Cheers . 🙂
si senor 🙂
The "Global Properties" of the SmartConsole, is as the image you shared.
What makes me doubt is why the traffic at a certain moment stops doing NAT (this is why the traffic starts to match with the Cleanup Rule).
This happens at times.
It is very strange.
Few times I helped people with this sort of issue, we solved it by clearing nat table. I know its intrusive and has to be done off hours, but seemed to do the trick
Andy
https://support.checkpoint.com/results/sk/sk32224
TAC is probably going to be necessary to get to the bottom of this.
Not sure why the port would matter here.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY