- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Checkmates,
I want your expert experience to validate the below Manual NAT and access control policy format.
I want internet users can access our internal server with the public IP_A, Is the below format valid? I am using the same public IP for others servers with different services ports, that's why i am using Manual NAT.
| Manual NAT and Access control policy rule matching | ||||
| 1 | NAT rule | |||
| name | Original source | original Destination | Translated destination | |
| AAAirport | any | Public IP_A | Private IP_A | |
| 2 | Access control policy | |||
| Name | Source | Destination | ||
| Access_AAAirport | Any | Public IP_A |
As long as you see the traffic in the logs (allowed or blocked) you know config is correct on arp level.
1. for access rules, destination will be public IP_A? - correct
Hi,
If I were you I would differentiate the NAT rules per service port. This allow you to handle the rules furthermore separately.
I usually follow this attitude.
But should work what you asked.
Akos
Hi @AkosBakos
I understand, I did different rule1 , rule2 , rule 3 to map the same public IP with private ip differently according to the services port. the above one is just for rule1, I did the same for others rules. So the above NAT rule and access rules format is valid. Right?
Hi @yeruel
I suggest you one-to-one correspondence. One NAT rule belogs to one Access rule. This is the best way.
Akos
Would indeed also recommend to make the rule more specific with a port like for example tcp443
Also make sure if needed proxy arp is in place for the public IP. Firewall needs to know the public IP belongs to him.
Unless the public IP is in the topology itself of the firewall (configured direct on a interface)
Best way to test if arp works correct is to see traffic logs, if you see traffic towards the public IP you know arp works.
Hi @Lesley
I seems, only one Public_IP relevant here, so proxy ARP is not relevant (yet)
Yes, access rules are recommended to separate too.
Akos
1. for access rules, destination will be public IP_A?
2. If we have more than one public IP for example
213.66.95.13---External gateway interface
213.66.95.10---will be used for Hide NAT IP address
213.66.95.11, 12 will be used to publish servers for accessing from internet.
213.66.95.10,11,12 are added in the ARP gaia portal.
ARP 213.66.95.10, 213.66.95.11, and also 213.66.95.12 in the arp with real ip address 213.66.95.13 and outside interface.
Any advice please?
Hi @yeruel
"213.66.95.10,11,12 are added in the ARP gaia portal" -> don't forget to add to all members this enties (both cluster members)
The guide is here: https://support.checkpoint.com/results/sk/sk30197
---I deleted my sentence, my wording was misleadning---
Akos
As long as you see the traffic in the logs (allowed or blocked) you know config is correct on arp level.
1. for access rules, destination will be public IP_A? - correct
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 23 | |
| 18 | |
| 7 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY