> Source: [sk105302](https://support.checkpoint.com/results/sk/sk105302)

# sk105302 - Traffic NATed behind an Address Range object is always NATed behind the same IP address

| Property | Value |
|----------|-------|
| Solution ID | sk105302 |
| Date Created | 2015-04-16 |
| Last Modified | 2025-09-11 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- When using Manual Hide NAT behind an Address Range object instead of a single IP address, the translated (NATed) IP address used is always the same IP address.

## Cause

When using Manual Hide NAT to hide one or more networks behind the Security Gateway, it is possible to hide the traffic behind an Address Range object instead of a single IP address. This may be desired if a high amount of traffic is expected from the network being NATed because it is only possible to NAT around 50,000 connections behind one IP address.

When traffic is NATed behind an Address Range object, the algorithm used to calculate which IP address is used is based on the original Source IP address. If all traffic tests are performed using the same Source IP address, then the translated source IP address will always be the same as well.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
