# Course 32 - Checkpoint CCSA R80 | Episode 7: NAT, Gateway Redundancy, and Software Blades Page: https://stenobird.com/podcast/cybercode-academy-7578615/course-32-checkpoint-ccsa-r80-episode-7-nat-gateway-redundancy-and-software-blades Text version: https://stenobird.com/podcast/cybercode-academy-7578615/course-32-checkpoint-ccsa-r80-episode-7-nat-gateway-redundancy-and-software-blades.md Podcast: [CyberCode Academy](https://stenobird.com/podcast/cybercode-academy-7578615) Published: 2026-05-07T06:00:03+00:00 Episode link: https://www.spreaker.com/episode/course-32-checkpoint-ccsa-r80-episode-7-nat-gateway-redundancy-and-software-blades--71508370 Audio file: https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/71508370/building_secure_and_redundant_network_gateways.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-32-checkpoint-ccsa-r80-episode-7-nat-gateway-redundancy-and-software-blades Duration seconds: 1070 ## Resource In this lesson, you’ll learn about: advanced NAT, redundancy (ClusterXL), and Software Blades in Check Point R801. Advanced NAT Implementation In Check Point R80, you can combine manual + automatic NAT πŸ”Ή Real Scenario Manual Destination NAT Public IP β†’ Internal web server (port 80) Automatic Hide NAT Internal server β†’ Internet (outbound traffic) πŸ”Ή Key Insight Same server can use: Static NAT (incoming) Hide NAT (outgoing) πŸ”Ή Troubleshooting Tip Ensure NAT rules are applied to: Correct policy targets (gateways) πŸ‘‰ Wrong target = NAT not working2. Gateway Redundancy with ClusterXL High availability is achieved using: ClusterXL πŸ”Ή Mode 1: High Availability (HA) Active / Standby βœ” Behavior One gateway is active Backup takes over if failure occurs βœ” Important Feature When failed gateway returns: System keeps current active node πŸ‘‰ Prevents unnecessary failoversπŸ”Ή Mode 2: Load Sharing Active / Active βœ” Behavior Multiple gateways handle traffic simultaneously βœ” Methods Multicast Unicast πŸ‘‰ Improves performance and scalability3. Software Blades (Modular Security) Check Point uses: Check Point Software Blades πŸ”Ή Examples VPN Identity Awareness Intrusion Prevention (IPS) πŸ”Ή Benefit Enable only what you need Reduce overhead Customize security stack 4. URL Filtering (Web Control)πŸ”Ή Purpose Block harmful or unwanted websites πŸ”Ή How It Works Use: Categories (e.g., gambling, malware) Inline layers for detailed control πŸ‘‰ Example: Block gambling Allow educational sites 5. Application Control (Granular Visibility)πŸ”Ή Advanced Filtering Control sub-applications, not just websites πŸ”Ή Example Allow: Facebook Block: Facebook games πŸ‘‰ Fine-grained policy enforcement6. Policy Actions (Traffic Handling)πŸ”Ή Available Actions Accept β†’ Allow traffic Drop β†’ Silently block Reject β†’ Block + notify sender Ask β†’ Promp… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-32-checkpoint-ccsa-r80-episode-7-nat-gateway-redundancy-and-software-blades/transcription-requests` β€” Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybercode-academy-7578615/course-32-checkpoint-ccsa-r80-episode-7-nat-gateway-redundancy-and-software-blades.md` β€” Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.