Re: same internal host mapped to 2 different static ip address hi mate thanks for ur reply. but i tried as u said. with the first rule permitting from intranet to the ext_ip1 .my next rule is permit internet that is any to ext_ip2. third is a cleanup rule. with this the intranet is able to access both the ext_ip1 and ext_ip2 as well. i guess checkpoint matches both the sources and destination in the rule base and not just the source in the rules. cause in the fw log i can see that when intranet is accessing the ext_ip2 it matches the second rule. the rule base which u mentioned to me is not working man . and right now my policies are only for permitting form external networks to my internal hosts on the natted ip. regards sebastan |