Security Management behind NAT

Overview

Configuring NAT for Control Connections on the Security Management Server

  1. From the left navigation panel, click Gateways & Servers.

  2. Double-click the Security Management Server object.

  3. From the left navigation tree, click NAT.

  4. Select Add Automatic Address Translation rules.

  5. In the Translation method field, select Static.

  6. Configure the applicable IP address.

    In our example - 192.168.55.1

  7. Select one of these two options:

    • Install on Gateway - The Security Gateway that performs this NAT. In our example, the local Security Gateway that is directly connected to the Security Management Server (item 2 in the diagram).

    • Do not create automatic NAT rules - The Security Management Server is behind a non-Check Point device that handles the NAT.

  8. Connections from Security Gateways to this server. Select one of these options:

    • Based on topology configuration (use the server's translated or original IP address).

    • Use this server's original IP address.

    • Use this server's translated IP address.

  9. Optional: Select Apply for Security Gateway control connections - This option performs NAT on VPN control connections to and from the Security Management Server. This makes it possible to install a policy or collect logs across a NAT gateway.

  10. Click OK.

  11. Install the Access Control Policy on the applicable Security Gateways.

Configuration on the Security Gateway

For each Security Gateway, you can decide whether to use the definitions on the Management Server / Log Server or to override the settings of the Management Server / Log Serverand configure other settings for the specific Security Gateway.

To configure management behind NAT settings for a specific Security Gateway:

  1. In SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on., go to the Gateways & Servers view, and double-click the relevant Security Gateway object.

  2. In the Security Gateway object editor, from the left navigation menu, select NAT > Management / Log Servers.

  3. The default option is Use Management Server / Log Server settings.

  4. To override the default settings, select one of these options:

    • Use the remote server's original /translated IP address based on the topology

    • Use only the original IP address for the remote servers.

    • Use only the translated IP address for the remote servers.

Notes: