- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Good morning,
nice to meet you.
It's my first time I configured VSX, and with humility, I I say I'm having problems configuring the NAT rules.
AS you can see we deployed two VSs (one Internal and one External).
We would like to simplify as much as possible the NAT rules.
For example, we tried to NAT management network (Static NAT rule) behind Public IP, but it does not work.
Any suggestions about and how to configure NAT rules and where (which VS) in the easiest way to see less logs in the SmartDashboard are really appreciated (maybe with some examples).
Is there something wrong? I am really grateful to you.
Thanks, best regards.
Just a quick suggestion:
> we tried to NAT management network (Static NAT rule) behind Public IP, but it does not work.
This is your idea:
- Real SRC: mgmt network
- Real DST: Any
- Translated Source: the external IP of the firewall (so you configure a dynamic PAT, or "hidden", not "static")
- Translated DST: = (he same as the real DST)
You can use the "hide the traffic behind the external IP", but personally, I prefer an explicit manual NAT rule.
Hello, I posted all screenshots, but I am lost on this configuration 😅, any suggestion about configuration?
Do you have screenshot of how rules are configured?
It was attached, and now it's deleted. The NAT rule on the screenshot was a static one from, for example, Net1 to Net1. Hence my note about PAT to the external iface.
Hello, so, I posted all screenshots!
When using manual NAT, ensure that Proxy ARP is properly configured and that the "Merge manual proxy ARP configuration" option is selected in the Global Properties under NAT settings.
Hello, as you can see I posted screenshots.
In case, which IP address do I need to use as a proxy ARP?
For outgoing PAT (to the external IP of the firewall/cluster) you do not need proxy ARP.
Hi everyone,
so, at the end, today I simply created an automatic NAT rule (Oject and then Nite, Hide Behing the Gateway).
There is NAT on External VSX (enabled NAT, Hide behind the Gateway).
I think at the moment is the best solution!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 23 | |
| 15 | |
| 14 | |
| 12 | |
| 10 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY