> Source: [sk170633](https://support.checkpoint.com/results/sk/sk170633)

# sk170633 - Nat rule does not work on ClusterXL after upgrade to R80.20 or higher

| Property | Value |
|----------|-------|
| Solution ID | sk170633 |
| Date Created | 2020-11-26 |
| Last Modified | 2020-11-30 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81 (EOS) |
| OS | Gaia |

## Symptoms

- * <br />

  After an upgrade to R80.20 or higher, NAT rule with destination IP of the Cluster primary member is ignored, when secondary Cluster member is active, and the traffic pass without the destination NAT translation.

  <br />

  Example scenario:  

  Cluster Virtual IP: x.x.x.92  

  Primary Cluster member's physical IP: x.x.x.93  

  Secondary Cluster member's physical IP: x.x.x.94  

  NAT Rule is created to translate Destination x.x.x.93 which is the primary Cluster member's physical IP to an internal IP z.z.z.187  

  Original traffic flow: y.y.y.225 -\> x.x.x.93  

  Translated traffic flow when NAT is matched: y.y.y.225 -\> z.z.z.187
* <br />

  The same NAT rule works with R80.10 and lower firewall versions when either primary or secondary Cluster member is active.

  <br />

* <br />

  The issue is not seen when primary Cluster member is active.

  <br />

## Cause

After a fail-over the primary Cluster member's physical IP which is used in the NAT rule becomes the physical IP of the standby member as per cluster status.

Hence as per NAT rule, the now active member needs to translate this to the standby physical IP. A code improvement was done to prevent NAT that changes the standby Cluster member's physical IP at the active Cluster member.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
