> Source: [sk112656](https://support.checkpoint.com/results/sk/sk112656)

# sk112656 - Security Gateway is trying to send logs to the NAT address of the Log server instead of sending to its primary address

| Property | Value |
|----------|-------|
| Solution ID | sk112656 |
| Date Created | 2016-08-08 |
| Last Modified | 2017-10-24 |
| Technical Level | Advanced |
| Products | Security Management Server, Multi-Domain Security Management Server, Logging & Status |
| Versions | R82.10, R82, R81.20, R82.10, R82.10, R82.20, R81.20, R82, R82.20, R82.20, R81.20, R82 |

## Symptoms

- * Log server object is configured with static NAT.
* Problematic Security Gateway has connectivity to internal IP of log server but still decide to use the NAT IP.
* *netstat -nap \| grep :257* command on the Security Gateway shows that the Security Gateway is trying to establish connection to the NAT address that is configured on the log server object.
* If it fails to communicate with the NAT address, the Security Gateway will try to connect to the backup log server that is configured.

## Cause

Since the log server object type is defined as "CheckPoint Host", it sometimes fails to get the correct IP address of the object.

If the log server object type is defined as "CheckPoint Gateway" type object, the IP resolving will know to consider all the network topology and connect to the correct IP address.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
