> Source: [sk112099](https://support.checkpoint.com/results/sk/sk112099)

# sk112099 - Allowing access to Endpoint Security Management and Policy Server using its NAT address

| Property | Value |
|----------|-------|
| Solution ID | sk112099 |
| Date Created | 2016-06-22 |
| Last Modified | 2020-12-01 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | R81 (EOS) |
| OS | Gaia |

## Solution

### Important: This solution assumes that you have worked with your Internet Service Provider or network department to set up Static NAT (one-to-one NAT) for the Endpoint Security Server or Policy Server (i.e. Private IP address \<---\> Public IP address), and that it will be able to communicate/route with other public IP Servers/Clients. Or inversely, you have setup other routing techniques on your network environment to route packets between public IP address Servers/Clients and the Endpoint Security Policy Server private IP address.

### For R77.30.02 and newer versions:

Follow the the procedure below.

When setting up an external NAT for an Endpoint Security Policy Server, you first need to add it via SmartEndpoint, establish SIC internally with the Endpoint Security Management Server, and install database.

Proceed as follows:

1. Login to SmartDashboard. Double-click the Endpoint Management/Policy Server object in the 'Objects Tree \> Network Objects'.
2. In NAT, configure "Hide behind IP Address".  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk112099/sk1120991607100303.png)

<br />

1. Click "OK".
2. Save changes.

**Limitation:**  
"Hide behind Gateway" option cannot be used.  
Using this option will force Endpoint clients to try to connect to 0.0.0.0 IP of NAT.

### For R77.30.01 HF1 version:

Download and install the [following hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&fileid=50303) on the Endpoint Security Management and all Policy Servers.

Follow the procedure above for R77.20.02 and newer versions.

### For R77.30.01 and R77.20.01 version:

It is recommended to upgrade to R77.30.02 or newer.

Check Point recommends to always upgrade to the most recent version (upgrade Endpoint Security Management Server).

### For other versions:

Please contact Check Point technical support

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
