- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I have a question regarding NAT behavior in relation to IPSEC tunnels. Consider this scenario:
FW1 -> FW2 (through IPSEC VPN)
Policy on FW1 ---
Source: HostObj1 (host object with private IP, NAT to public IP - automatic NAT rule created)
Destination: HostObj2, HostObj3, ...
VPN: MyCommunity1
Action: Accept
---
My question, will source NAT apply to this traffic since VPN involved? If not, is there any setting that controls this or documentation that supports it?
Thanks in advance.
Just make sure NAT setting is NOT disabled inside vpn community object.
Andy
Yes, source NAT will apply.
Just make sure NAT setting is NOT disabled inside vpn community object.
Andy
Thanks! So if I understand correctly, source NAT will apply unless this is set?
Thats right!
Andy
VPN Communities - Advanced (checkpoint.com)
Disable NAT Inside the VPN Community
Even if NAT is configured it is possible to disable NAT inside the VPN community. If NAT is disabled, when a host behind a community member opens a connection with another host behind a community member, the original IP addresses are used. Other connections use the translated address.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY