> Source: [sk66381](https://support.checkpoint.com/results/sk/sk66381)

# sk66381 - How to configure Management behind NAT in Security Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk66381 |
| Date Created | 2012-01-01 |
| Last Modified | 2025-10-22 |
| Technical Level | General |
| Products | Security Management Server |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

**Background**

Although manual/automatic static NAT is configured on the Management Server, Security Gateway 80 still fetches policy/logs to the real IP address of the Security Management Server instead of to the NAT address.

The appliance recognizes that the Security Management Server is behind NAT only if the Automatic Static NAT property is configured on the Security Management Server object in SmartDashboard, and **Apply for Security Gateway control connections** is selected.

![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk66381/1100nat1706210036.JPG)

**Configure automatic static NAT on the Security Management Server object in SmartDashboard:**

1. From the **Install on** drop-down list, choose the applicable Gateway that performs the static NAT.
2. Select **Apply for Security Gateway control connections** and install policy on the appliance.

If manual NAT is already configured on the Security Management Server, there is no harm in leaving the manually created rule intact and installing both NAT rules. You can also put the manual NAT rule way above the automatically created NAT rule, so the auto rule will never be actually matched.

**Notes:**

* It is not sufficient to configure automatic static NAT on the Security Management Server object. You **must** select **Apply for Security Gateway control connections**in order for the appliance to connect to the Management Server's NAT IP address.
* If the Gateway that actually performs the static NAT on the Security Management Server is not managed by the same server that manages the appliance, the user must create a dummy Gateway object representing the real Gateway and select it from the drop-down list. Selecting the appliance from the list and the **Apply for Security Gateway control connections** property will not work.
* A management dummy object should not be created as a Check Point host as this will cause SIC issues.
* If management was already defined, and you want to change the settings of the override management / log server IP address, in the Gaia WebUI **Management Page** you must first click the **Test connection** button, and then click on the IP address hyperlink.
* Alternatively, you can use the following Clish command to set the log and Management Server:  
  `set security-management local-override-mgmt-addr`  
  **For example:**   
  `set security-management local-override-mgmt-addr true mgmt-address 172.30.74.45 send-logs-to local-override-log-server-addr addr 172.30.74.45`

*** ** * ** ***

Customer asked: (1100 appliance)

Q: "After following these steps, the off-site 1100 appliance connects successfully to the Security Management server and can fetch policy. However, my other on-site perimeter Gateways can no longer fetch policy from the Security Management Server, nor send logs to the Security Management Server because it is attempting to send logs to the NAT IP instead of the real IP of the Security Management Server.

A: It is possible to locally decide, on the 1100 appliance's WebUI (Security Management Server Connection screen), what will be the Management (and/or) Log server IP address that the Gateway will use, and override the information in the policy.

This way it is possible to fix the issue for specific gateways without disrupting other gateways.

<br />

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk66381/Security_Management_Server_Connection.jpg "TITLE")  

**Related Documentation**

* [sk100583 - Configuration of Security Management behind NAT](https://support.checkpoint.com/results/sk/sk100583)
* [R82 Quantum Security Management Administration Guide](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SecurityManagement_AdminGuide/Content/Topics-SECMG/Security_Management_behind_NAT.htm)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
