> Source: [sk163320](https://support.checkpoint.com/results/sk/sk163320)

# sk163320 - Policy Based Routing (PBR) is not performed when using Hide NAT

| Property | Value |
|----------|-------|
| Solution ID | sk163320 |
| Date Created | 2019-10-31 |
| Last Modified | 2025-04-03 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * PBR policy rule was set to match specific source IP address, and according to the PBR policy, the packet should go out from the interface matched the PBR rule.  
  Instead the traffic is sent based on the static routing table, and the PBR rule is not matched.
* The Source IP is also hide NATed.

## Cause

Previous to R80.20 the allocation of hide-NAT port (and defining the hide NAT address) was done in the OUTBOUND, after the PBR was calculated.  

In R80.20 and R80.30 the allocation of hide-NAT port (and defining the hide NAT address) is done in the INBOUND, before the PBR calculation.  

In R80.40 and above the PBR behavior has been changed to ensure PBR calculation is performed on the original IPv4 addresses, and will not match changes to IP headers performed by NAT.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
