> Source: [sk119304](https://support.checkpoint.com/results/sk/sk119304)

# sk119304 - NAT is not applied to traffic generated by a Virtual System itself in VSX Cluster

| Property | Value |
|----------|-------|
| Solution ID | sk119304 |
| Date Created | 2017-07-29 |
| Last Modified | 2025-03-31 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * NAT is not applied to traffic generated by a Virtual System itself in VSX Cluster (e.g., a connection from VS to Check Point cloud).

  Example topology:  

  ---\[Virtual System\]{wrp}---\[VSX Cluster Member\]{eth0} --- \[Network\]

  Desired traffic behavior:  

  Traffic generated by a Virtual System should be NATed behind the configured IP address (e.g., so that Virtual System could update Anti-Bot signatures from Check Point cloud).
* Neither Automatic NAT enabled in the Virtual System's object, nor Manual NAT rule works -  

  NAT is not applied to this traffic - packets are still sent with the Virtual System's user-defined IP address (configured in VS object).

* FW Monitor (example syntax: `fw monitor -e "accept host(<Destination_IP_Address>) and icmp;" -p all`) shows that NAT is not applied to the Virtual Systems' IP address - packets are sent with the user-defined IP address of the Virtual System.

## Cause

The NAT process is implemented only once for the traffic originated from within the Firewall in the outbound chain.

If the interface's real (funny) IP address is NATed to the user-defined IP address, which was chosen based on the routing decision, then the NAT rule for the source IP address will *not* be implemented.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
