- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi,
I want to create automatic NAT to an internal host from two external IPs. However, in Host->NAT page I can set only one external IP. At the moment I have solved this problem by creating manual NAT rule for the second external IP but I wonder if there us more nifty way to solve this and have automatic NAT for both external IPs?
You cannot use two Public IPs and NAT them. This will give you problems with return packets as well.
What you can do, you can setup an Internet Load Balancer with multiple connections and place it in front of your Firewall. This will give you the possibility of having more than one IPs per public service and the replies can be setup to return through the same source IP. Additionally in case you ISP is down you are still going to be available.
Thanks,
Charris
Hmm, you are actually right. Thanx for the tip mate. Much appreciated.
There is only the way over the manual NAT rule.
1) Use an automatic NAT rule for the first external IP.
2) Use an manuell NAT rule for the second IP and set the proxy arp entry for the second IP in the WebGUI.
Alternatively, you can use two manual NAT rules with two proxy arp entries.
Here you can find a flowchart of how nat is implemented:
R80.x Security Gateway Architecture (Logical Packet Flow)
Regards,
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY