- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Dear Checkmates,
I'm having problem creating DST NAT rule for an ICMP traffic, I'm forced to create a rule with services as "ANY" for this to work.
Can someone let me know if this is a limitation and so please share the relevant document from Check Point.
Thanks in advance!
=======
WR,
FH
The NAT rulebase only permits usage of TCP and UDP services.
I don't believe this is explicitly documented as SmartConsole provides an appropriate error when you attempt this configuration.
This is also a long-standing limitation going back to the earliest days of the product.
Having said that, the NAT rulebase only applies if the traffic is permitted by the Access Policy.
NAT (Network Address Translation) is a feature of the Firewall Software Blade
and replaces IPv4 and IPv6 addresses to add more security. NAT protects the identity of a network and does not show internal IP addresses to the Internet.
The Security Gateway can change:
The source IP address in a packet.
The destination IP address in a packet.
The TCP / UDP port in a packet. (ICMP is not TCP or UDP)
https://community.checkpoint.com/t5/Management/Destination-NAT-with-ICMP/m-p/19275#M16164
sk66506: ICMP Error packets are not translated according to NAT rulebase
The NAT rulebase only permits usage of TCP and UDP services.
I don't believe this is explicitly documented as SmartConsole provides an appropriate error when you attempt this configuration.
This is also a long-standing limitation going back to the earliest days of the product.
Having said that, the NAT rulebase only applies if the traffic is permitted by the Access Policy.
You get a validation error when you try to sneak ICMP in a group in the rule. If you try to select icmp itself you cannot find it to select in the drop down menu
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY