> Source: [sk142833](https://support.checkpoint.com/results/sk/sk142833)

# sk142833 - How to create manual NAT rules in Many-To-Few mode

| Property | Value |
|----------|-------|
| Solution ID | sk142833 |
| Date Created | 2018-12-17 |
| Last Modified | 2021-02-17 |
| Technical Level | General |
| Products | SmartConsole |
| Versions | R82.10, R82.x, R82.20, R82, R81.20 |

## Solution

In some configurations, using one NAT IP address to hide internal networks might not be sufficient. When this is the case, you can create manual NAT rules in Many-To-Few mode.  

**Note**: If the addresses used for NAT are not routed to the Gateway, configure proxy ARP for the addresses.

### Instructions for R80.x

1. In SmartConsole, go to **Security Policies**.
2. Open the NAT Rule Base.
3. Create a Manual NAT rule in **Original Source**, add an Internal Network object or a Group of Internal Network objects.
4. In **Translated Source**, add an Address Range object with the Hide NAT Method.
5. Install the Security Policy.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk142833/NAT_r801812171950.JPG)

### Instructions for R77.x

1. In SmartConsole, open the **NAT Rule Base**.
2. Create the Manual NAT rule.
3. In **Original Packet Source**, add an Internal Network object or a Group of Internal Network objects.
4. In **Translated Packet Source**, add an Address Range object with the Hide NAT Method.
5. Install the Security Policy,

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1545103002835/NAT1812171939.jpg)

**Related Solutions:**

* [sk103356: Dynamic NAT port allocation feature](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk103656)
* [sk105302: Traffic NATed behind an Address Range object is always NATed behind thesame IP address](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105302)
* [sl120296: Carrier Grade NAT (CGNAT)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk120296)
* [sk140432: "NAT Hide failure " error in SmartLog / SmartView Tracker](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk140432)
* [sk114395: Automatic creation of Proxy ARP for Manual NAT rules on Security Gateway R80.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114395)
* [sk30197:Configuring Proxy ARP for Manual NAT](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk30197)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
