> Source: [sk164717](https://support.checkpoint.com/results/sk/sk164717)

# sk164717 - Link probing may not work with satellite peers that are behind Hide-NAT

| Property | Value |
|----------|-------|
| Solution ID | sk164717 |
| Date Created | 2020-01-16 |
| Last Modified | 2020-01-19 |
| Technical Level | Advanced |

## Symptoms

- When the satellites are behind Hide-NAT, the Center Security Gateway may drop its own replies towards the satellites on clean-up rule.  
This occurs even though probing is allowed by implied rules.

## Cause

A relatively common scenario is having a Center gateway, with two or more external interfaces that are probed by satellites, using the link selection method "Link probing".

The satellites probe the Center gateway by sending requests via UDP port 259, at a set interval, towards the configured interfaces on the Center gateway object's link selection settings (which is why this method works between Check Point gateways only).

The Center gateway then replies to those requests using the same port.

The Kernel shows that the requests and replies are being handled by different CPU/instances, causing the Center gateway to identify its own reply as a separate connection.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
