> Source: [sk93588](https://support.checkpoint.com/results/sk/sk93588)

# sk93588 - How to create "Allow and Forward" rule on Locally Managed Spark Firewall

| Property | Value |
|----------|-------|
| Solution ID | sk93588 |
| Date Created | 2013-07-19 |
| Last Modified | 2022-07-26 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1500, 1600, 1800, 910 |

## Solution

To permit and direct incoming traffic from the Internet to a specific computer and/or servers inside your internal network with a specific service, you have to define an object that will represent the Server.

1. With a web browser, connect to the appliance Web interface and log in.

2. From the left navigation panel, click **Access Policy** \> **Servers** (in the **Firewall** section)

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk93588/newserver20200423083646.png)
3. Click **\* New**.

   The **New Server Wizard** opens.
4. Configure the server type and click **Next**:

   There are 5 common built-in server types: Mail, DNS, Web Server, FTP, and Citrix Server.

   If you want to create a custom server, select only the **Other server** option and configure the required settings.

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk93588/page120200423083729.png)
5. Configure the server definitions and click **Next**:

   1. In the **Name** field, enter the object name
   2. In the **IP address** field, enter the IPv4 address of the server
   3. In the **Comments** field, enter the object description (optional)
   4. Select the applicable options (see the Administration Guide for your version)

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk93588/page220200423084104.png)
6. Configure the server access settings and click **Next**:

   Select the applicable zones to create the corresponding Access policy rule.

   Configure the applicable ping and logging options (see the Administration Guide for your version).

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk93588/page320200423084242.png)
7. Configure the server NAT settings and click **Finish**:

   To configure port forwarding:
   1. Select either **Hide Behind Gateway** or **Static NAT**

   2. Select **Redirect from port**

   3. Enter the port, on which the appliance needs to listen to the incoming traffic

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk93588/page420200423084921.png)

For more information, refer to the [**Administration Guide**](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=documents&product=512) for your version \> section **Defining Server Objects**.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
