> Source: [sk39327](https://support.checkpoint.com/results/sk/sk39327)

# sk39327 - How to configure IP Pool NAT addresses in Check Point Cluster

| Property | Value |
|----------|-------|
| Solution ID | sk39327 |
| Date Created | 2009-04-14 |
| Last Modified | 2021-03-31 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Solution

### Background

IP Pool NAT is a type of NAT, in which source IP addresses from remote VPN domains are mapped to an IP address drawing from a pool of registered IP addresses.

IP Pool NAT ensures proper routing for two connection scenarios:

* SecuRemote/SecureClient to MEP (Multiple Entry Point) gateway connections.
* Gateway to MEP gateway connections.

**Note:** Regarding the support of IP Pool NAT with CoreXL refer to [sk76800.](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk76800)

### Configuration

1. Enable the IP Pool NAT:

   1. In SmartDashboard, go to the ***Policy*** menu - click on the ***Global Properties...***.

   2. In the left tree, click on the ***NAT - Network Address Translation***.

   3. In the ***IP Pool NAT*** section, check the box ***Enable IP Pool NAT***.

      [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk39327/Global_Properties.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk39327/Global_Properties.png "Click the image to see it in full size in a new tab/window")
   4. Configure the desired track settings.

   5. Click on OK.

   6. Go to the ***File*** menu - click on the ***Save***.

2. Create a *Network* , *Group* (of Networks), or *Address Range* object that represents the IP Pool NAT addresses.

   Note: Refer to the "Notes" section.
3. Configure the IP Pool NAT:

   In cluster, the IP Pool NAT is configured on *each* cluster member's object, and not in the cluster object.
   1. In SmartDashboard, open the Cluster object properties.

   2. In the left tree, expand the ***NAT*** - click on the ***IP Pool NAT***.

   3. Select either the ***Define IP Pool NAT on each cluster member*** option, or the ***Define IP Pool NAT on cluster member interfaces*** option (refer to the "Notes" section.).

      Configure additional desired settings (refer to VPN Administration Guide).
      *Example* :  
      [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk39327/NAT_IP_Pool_NAT.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk39327/NAT_IP_Pool_NAT.png "Click the image to see it in full size in a new tab/window")
   4. In the left tree, go to ***Cluster Members***.

   5. Select each cluster member - click on the ***Edit...*** button.

   6. Go to the ***IP Pool NAT*** tab.

   7. Check the box ***Use IP Pool NAT***.

   8. Select the relevant Network / Group (of Networks) / Address Range object.

      Note: Refer to the "Notes" section.
      *Example* :  
      [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk39327/Cluster_Members_IP_Pool_NAT.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk39327/Cluster_Members_IP_Pool_NAT.png "Click the image to see it in full size in a new tab/window")
   9. Click on OK.

   10. Go to the ***File*** menu - click on the ***Save***.

4. Install the Network Security policy on the cluster object.

### Notes: {#Notes}

* The correct way to configure IP Pool NAT on clusters depends on whether this is a Cluster Load Sharing or Cluster High Availability configuration.

  * In Cluster Load Sharing mode:

    IP Pool should be divided to different pools on each cluster member - this is to prevent race-conditions where two members allocate the same free IP. The allocation mechanism state is not synchronized.
  * In Cluster High Availability mode:

    IP Pool can be the same on all cluster members - this will allow Standby members to continue allocating IP addresses from the pool in case they become Active (after cluster failover). Configuring different pools on different cluster members is also supported.

### Related documentation

* VPN Administration Guide ([R77.X](http://downloads.checkpoint.com/dc/download.htm?ID=24849), [R80](http://downloads.checkpoint.com/dc/download.htm?ID=46536), [R80.10](http://downloads.checkpoint.com/dc/download.htm?ID=53104) / [R80.10](http://downloads.checkpoint.com/dc/download.htm?ID=53105)) - chapter "Multiple Entry Point VPNs" - section "Configuring MEP" - subsection "Configuring IP Pool NAT"
* ClusterXL Administration Guide ([R77.X](http://downloads.checkpoint.com/dc/download.htm?ID=24800), [R80.10](http://downloads.checkpoint.com/dc/download.htm?ID=54804))
* Security Management Server Administration Guide ([R77.X](http://downloads.checkpoint.com/dc/download.htm?ID=24830), [R80](http://downloads.checkpoint.com/dc/download.htm?ID=46534) / [R80](http://downloads.checkpoint.com/dc/download.htm?ID=46535), [R80.10](http://downloads.checkpoint.com/dc/download.htm?ID=54842))

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
