> Source: [sk185159](https://support.checkpoint.com/results/sk/sk185159)

# sk185159 - Network Address Translation Pool Fails to Load Share with ISP Redundancy Active/Active

| Property | Value |
|----------|-------|
| Solution ID | sk185159 |
| Date Created | 2026-08-04 |
| Last Modified | 2026-08-11 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82 |
| OS | Gaia |

## Symptoms

- Administrators require outbound Internet traffic from an internal network, for example \`192.168.0.0/24\`, to be hidden behind a defined Network Address Translation (NAT) IP pool. The same environment also requires outbound traffic load sharing across two Internet Service Provider (ISP) links in an ISP Redundancy Active/Active design. When Hide NAT behind the gateway is configured with IP Pool NAT, Proxy Address Resolution Protocol (Proxy ARP), and ISP Redundancy: Traffic passes through both ISP links. The translated source IP address is the external Security Gateway IP address, for example \`10.0.0.2\`. The translated source IP address is not one of the required NAT pool addresses, for example \`10.0.0.5\` or \`10.0.0.6\`. When Manual NAT rules use the required NAT IP pool range: - Traffic passes. - The source IP address is translated to the required NAT pool addresses. - ISP Redundancy Active/Active load sharing across both ISP links does not occur. When Dynamic Objects are used as a workaround: - Traffic passes. - The NAT pool is used. - ISP Redundancy Active/Active load sharing across both ISP links still does not occur. The required design cannot be achieved as configured: - Either traffic uses both ISP links, but NAT uses the Security Gateway external IP address. - Or traffic uses the required NAT pool, but ISP Redundancy Active/Active load sharing does not occur. Administrators also report concern about possible Hide NAT IP pool exhaustion or translated-source port exhaustion.

## Cause

NAT Pool with ISP Redundancy is supported only with ISP Redundancy Active/Passive mode, also known as Primary/Backup mode.  

The required design combines two conditions that are not supported together:  

- NAT Pool source translation for outbound traffic.  
- ISP Redundancy Active/Active mode, also known as Load Sharing mode.  

In Active/Active mode, ISP Redundancy distributes outbound connections across both ISP links. With Automatic Hide NAT behind the gateway, the translated source IP address follows the external Security Gateway IP address selected for the outbound path.  

Manual NAT rules or Dynamic Objects can translate traffic to the required NAT pool addresses. However, these methods do not provide the supported integration required for ISP Redundancy Active/Active load sharing with NAT Pool.  

As a result, the system cannot provide both NAT Pool translation and ISP Redundancy Active/Active load sharing in the same configuration.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
