> Source: [sk178087](https://support.checkpoint.com/results/sk/sk178087)

# sk178087 - The implied NAT Rule Number 0 performs NAT on specific services

| Property | Value |
|----------|-------|
| Solution ID | sk178087 |
| Date Created | 2022-03-13 |
| Last Modified | 2023-03-20 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * Traffic on the TCP ports 18210 and 18264 still undergoes NAT through the NAT rule with the number 0, although the option "Disable NAT inside the VPN community" is selected in the VPN Community object.

* The traffic undergoes NAT in a Route-Based VPN tunnel, but passes without NAT in a Domain-Based VPN tunnel.

* If you do not use VPN, then the Security Gateway might apply the NAT rule with the number 0 on other ports than the TCP ports 18210 and 18264.

* Example of a Security Gateway log:

  Log Info
  > Blade: Firewall  
  > Product Family: Access  
  > Type: Connection

  Policy
  > Action: Accept

  NAT
  > Xlate (NAT) Destination IP: 0.0.0.0  
  > NAT Rule Number: 0

## Cause

When this traffic goes over a Route-Based VPN, the Security Gateway matches it to an implied NAT rule.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
