{"id":31629,"date":"2019-10-31T21:42:14","date_gmt":"2019-10-31T18:42:14","guid":{"rendered":"https:\/\/prohoster.info\/blog\/8-check-point-getting-started-r80-20-nat\/"},"modified":"2019-10-31T21:42:14","modified_gmt":"2019-10-31T18:42:14","slug":"8-check-point-getting-started-r80-20-nat","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/8-check-point-getting-started-r80-20-nat","title":{"rendered":"8. Check Point Getting Started R80.20. NAT","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"8. Check Point Getting Started R80.20. NAT\" src=\"\/wp-content\/uploads\/2019\/04\/685e0796b7dc1aaacdacbd9fb27be938.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nWelcome to lesson 8. This lesson is very important because upon its completion you will already be able to configure internet access for your users! It must be said that many stop their setup here \ud83d\ude42 But we are not among them! There's still much interesting ahead. Now, let's get to the topic of our lesson.<\/p>\n<p>As you probably guessed, today we will be talking about NAT. I am sure that everyone watching this lesson knows what NAT is. Therefore, we will not go into detail about how it works. I will just repeat that NAT is an address translation technology created to save 'public' IP addresses, which are routed on the Internet. <\/p>\n<p>In the previous lesson, you probably noticed that NAT is part of the Access Control policy. This is quite logical. In SmartConsole, NAT settings are placed in a separate tab. We will definitely take a look there today. Overall, in this lesson we will discuss types of NAT, set up internet access, and consider a classic example of port forwarding. That is, the functionality that is most often used in companies. Let\u2019s get started.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h3>Two Ways to Configure NAT<\/h3>\n<p>\nCheck Point supports two ways to configure NAT: <b>Automatic NAT<\/b> and <b>Manual NAT<\/b>. For each of these methods, there are two types of translations: <b>Hide NAT<\/b> and <b>Static NAT<\/b>. Generally, this looks like the picture here:<\/p>\n<p><img decoding=\"async\" alt=\"8. Check Point Getting Started R80.20. NAT\" src=\"\/wp-content\/uploads\/2019\/04\/8ac626e12eb07dd5900fb42a516ca706.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nI understand that it probably looks quite complex right now, so let's take a closer look at each type.<\/p>\n<h3>Automatic NAT<\/h3>\n<p>\nThis is the fastest and easiest way. NAT configuration is done literally in two clicks. All you need to do is open the properties of the desired object (whether it's a gateway, network, host, etc.), go to the NAT tab, and check the box \u201c<b>Add automatic address translation rules<\/b>\u201d. Here, you will also see the field \u2014 translation method. There are two, as mentioned above.<\/p>\n<p><img decoding=\"async\" alt=\"8. Check Point Getting Started R80.20. NAT\" src=\"\/wp-content\/uploads\/2019\/04\/c25b8cdbd0644c4a554faab230d7a53e.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<h4>1. Automatic Hide NAT<\/h4>\n<p>\nBy default, this is Hide. That is, in this case, our network will 'hide' behind some public IP address. The address can be taken from the external interface of the gateway, or you can specify another one. This type of NAT is often called dynamic or <b>many-to-one<\/b>, as multiple internal addresses are mapped to a single external one. This is naturally possible by using different ports during translation. Hide NAT works only in one direction (inside to outside) and is ideal for local networks when simple internet access is needed. If traffic is initiated from the external network, NAT will not operate as expected. This adds another layer of protection for internal networks.<\/p>\n<h4>2. Automatic Static NAT<\/h4>\n<p>\nHide NAT is great, but you may need to provide access from the external network to an internal server. For example, to a DMZ server, as in our case. In this situation, Static NAT can help. It is also quite simple to configure. You just need to change the translation method to Static in the object's properties and specify the public IP address to be used for NAT (see the image above). That is, if someone from the external network accesses this address (on any port!), the request will be forwarded to the server with the corresponding internal IP. Additionally, if the server accesses the internet, its IP will also change to the specified address. This is NAT in both directions. It\u2019s also called <b>one-to-one<\/b> and is sometimes used for public servers. Why 'sometimes'? Because it has one major drawback \u2013 the public IP address is fully occupied (all ports). You cannot use the same public address for different internal servers (with different ports). For instance, HTTP, FTP, SSH, SMTP, etc. To resolve this issue, Manual NAT can be used.<\/p>\n<h3>Manual NAT<\/h3>\n<p>\nThe feature of Manual NAT is that you need to create your own translation rules. In that same NAT tab in the Access Control Policy. Manual NAT also allows you to create more complex translation rules. You have access to fields such as: Original Source, Original Destination, Original Services, Translated Source, Translated Destination, Translated Services. <\/p>\n<p><img decoding=\"async\" alt=\"8. Check Point Getting Started R80.20. NAT\" src=\"\/wp-content\/uploads\/2019\/04\/7ed3a4786dd581312ca2c221e003f290.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThere are also two types of NAT possible here \u2013 Hide and Static.<\/p>\n<h4>1. Manual Hide NAT<\/h4>\n<p>\nHide NAT in this case can be used in different situations. Here are a couple of examples:<\/p>\n<ol>\n<li>When accessing a specific resource from the local network, you want to use a different address for translation (different from the one used in all other cases).<\/li>\n<li>In a local network, there are a huge number of computers. Automatic Hide NAT won't work here, as this setup allows for only one public IP address, behind which the computers will \u201chide.\u201d There may simply not be enough ports for the translation. As you recall, there are just over 65,000 of them. Each computer can generate hundreds of sessions. Manual Hide NAT allows you to set a pool of public <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/lir\/ipv4\/\"   title=\"IP addresses\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"801\">IP addresses<\/a>. This thus increases the number of possible NAT translations.<\/li>\n<\/ol>\n<p><\/p>\n<h4>2. Manual Static NAT<\/h4>\n<p>\nStatic NAT is used much more frequently when manually creating translation rules. A classic example is port forwarding. This is the case when requests from an external network are made to a public IP address (which may belong to a gateway) on a specific port, and the request is translated to an internal resource. In our lab work, we will forward port 80 to a DMZ server.<\/p>\n<h3>Video lesson<\/h3>\n<p>\n<center><div class=\"youtube-placeholder\" data-id=\"HXN8VDAM7yY\" onclick=\"loadVideo(this)\">\r\n        <img decoding=\"async\" src=\"https:\/\/img.youtube.com\/vi\/HXN8VDAM7yY\/hqdefault.jpg\" alt=\"Play video\" loading=\"lazy\" width=\"480\" height=\"360\" style=\"width:100%;height:auto;\">\r\n        <div class=\"play-button\"><\/div>\r\n    <\/div><\/center><br \/>\nStay tuned for more and join our <noindex><a rel=\"nofollow\" href=\"https:\/\/www.youtube.com\/channel\/UCKOESE8nBWQPuQmi994_YMA\">YouTube channel<\/a><\/noindex> \ud83d\ude42<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/tssolution\/blog\/448114\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u043e\u0431\u0440\u043e \u043f\u043e\u0436\u0430\u043b\u043e\u0432\u0430\u0442\u044c \u043d\u0430 8-\u0439 \u0443\u0440\u043e\u043a. \u0423\u0440\u043e\u043a \u043e\u0447\u0435\u043d\u044c \u0432\u0430\u0436\u043d\u044b\u0439, \u0442.\u043a. \u043f\u043e \u0435\u0433\u043e \u0437\u0430\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044e \u0432\u044b \u0443\u0436\u0435 \u0441\u043c\u043e\u0436\u0435\u0442\u0435 \u043d\u0430\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0432\u044b\u0445\u043e\u0434 \u0432 \u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442 \u0434\u043b\u044f \u0432\u0430\u0448\u0438\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439! \u041d\u0430\u0434\u043e \u043f\u0440\u0438\u0437\u043d\u0430\u0442\u044c, \u0447\u0442\u043e \u043c\u043d\u043e\u0433\u0438\u0435 \u043d\u0430 \u044d\u0442\u043e\u043c \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 \u0438 \u0437\u0430\u043a\u0430\u043d\u0447\u0438\u0432\u0430\u044e\u0442 \ud83d\ude42 \u041d\u043e \u043c\u044b \u043d\u0435 \u0438\u0437 \u0438\u0445 \u0447\u0438\u0441\u043b\u0430! \u0418 \u0443 \u043d\u0430\u0441 \u0435\u0449\u0435 \u043c\u043d\u043e\u0433\u043e \u0438\u043d\u0442\u0435\u0440\u0435\u0441\u043d\u043e\u0433\u043e \u0432\u043f\u0435\u0440\u0435\u0434\u0438. \u0410 \u0442\u0435\u043f\u0435\u0440\u044c \u043a \u0442\u0435\u043c\u0435 \u043d\u0430\u0448\u0435\u0433\u043e \u0443\u0440\u043e\u043a\u0430. \u041a\u0430\u043a \u0432\u044b \u0443\u0436\u0435 \u043d\u0430\u0432\u0435\u0440\u043d\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":23547,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-31629","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0414\u043e\u0431\u0440\u043e \u043f\u043e\u0436\u0430\u043b\u043e\u0432\u0430\u0442\u044c \u043d\u0430 8-\u0439 \u0443\u0440\u043e\u043a.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/8-check-point-getting-started-r80-20-nat\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd478. Check Point Getting Started R80.20. NAT | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0414\u043e\u0431\u0440\u043e \u043f\u043e\u0436\u0430\u043b\u043e\u0432\u0430\u0442\u044c \u043d\u0430 8-\u0439 \u0443\u0440\u043e\u043a.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/8-check-point-getting-started-r80-20-nat\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:42:14+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:42:14+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd478. Check Point Getting Started R80.20. NAT | ProHoster","description":"Welcome to lesson 8.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/8-check-point-getting-started-r80-20-nat","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd478. Check Point Getting Started R80.20. NAT | ProHoster","og:description":"\u0414\u043e\u0431\u0440\u043e \u043f\u043e\u0436\u0430\u043b\u043e\u0432\u0430\u0442\u044c \u043d\u0430 8-\u0439 \u0443\u0440\u043e\u043a.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/8-check-point-getting-started-r80-20-nat","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:42:14+00:00","article:modified_time":"2019-10-31T18:42:14+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"31629","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-08 20:40:18","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:13:29","updated":"2026-02-08 20:40:18","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31629","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=31629"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31629\/revisions"}],"predecessor-version":[{"id":157992,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31629\/revisions\/157992"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/23547"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=31629"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=31629"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=31629"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}