- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi guys,
I have a question about VPN ending behind NAT. We would like to use Route-based VPN. We have two remote sites each with its own management. On one site we have a CP appliance directly with its own public IP.
On the other side first there is edge router with its public IP lets say 1.2.3.4, this router is doing static NAT, behind this router there is a CP firewall which have IP statically NATed to lets say 10.10.10.10.
With route based VPN we created VTIs each with it's own IP attached to physical interface as stated in the documentation.
Route Based VPN (checkpoint.com)
"
You configure a local and remote IP address for each numbered VPN Tunnel Interface (VTI).
For each Security Gateway, you configure a local IP address, a remote address, and the local IP address source for outbound connections to the tunnel.
The remote IP address must be the local IP address on the remote peer Security Gateway.
More than one VTI can use the same IP Address, but they cannot use an existing physical interface IP address.
"
Now as the router is doing NAT to 10.10.10.10, how should I configure VPN on first site so it knows there is a NAT on remote site and to send traffic via VPN tunnel to public IP 1.2.3.4 and then 2.2.3.4 if both interfaces are on same physical interface?
thanks
If the gateway is subject to NAT and initiating a VPN connection, Link Selection needs to be set to the correct IP.
See: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SitetoSiteVPN_AdminGuide/Top...
Okay so In my case, based on the topology picture I attached to the post.
I should configure link selection on the GW that is not behind NAT, and I should put IP address of the NATed VTI to the field "statically NATed IP" or IP of physical interface or should I configure it on the device that is behind NAT?
thanks
This needs to be configured on the device behind NAT.
Specifically, on the object for the device which is behind NAT. This configuration on the object tells the Check Point firewall which IP to use when trying to connect to that peer.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 19 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY