vendor hub
Check Point
Everything on ronutz.com for Check Point, in one place: every tool, grouped by family, followed by every article. Tools compute locally in your browser; articles are grounded in vendor documentation.
Working with Check Point →
The career chapter: what the work with Check Point actually was, which accounts, which escalations, and what it certified.
The Check Point story in the industry section →
How Check Point got here: the acquisitions, the pivots, and the people whose work ended up inside the platform.
Check Point lineage →
What Check Point is made of, and who made it. Every acquisition below is verified against primary sources, with the product line it turned into where that connection is documented rather than inferred.
Certification prep
Tools (2)
More
Check Point NAT reachability checker
Why a correct-looking NAT delivers nothing. Works out whether anything will answer ARP for the translated address, which is usually where the traffic disappears.
Security & WAFCheck Point policy layer evaluator
Watch a connection cross ordered layers: which rule matched in each, whether an accept meant allowed or merely proceed, and where a drop logged nothing.
Security & WAF
Articles (4)
More
Check Point NAT that logs nothing: proxy ARP and the failure one layer down
A manual static NAT onto an address in the gateway's own subnet installs cleanly, looks correct, and delivers nothing. There is no drop in the logs because nothing arrived to be logged. The answer is at layer 2, and automatic NAT handles it while manual NAT never has.
Security & WAFReadCheck Point NAT: Automatic Versus Manual, Hide Versus Static, and Proxy ARP
Check Point can generate NAT rules from an object's own properties or let you write them yourself, and the two behave differently in ways that matter. The single most common manual-NAT fault has nothing to do with the rule: the gateway is not answering ARP for an address it is translating to.
Security & WAFReadCheck Point Policy Layers: Ordered, Inline, and Shared
Layers let one rule base be several. Traffic must be accepted by every ordered layer to pass, an inline layer is a sub-policy hanging off a single rule, and a shared layer is one policy reused across packages. The accept semantics are what people get wrong.
Security & WAFReadThe Check Point Rule Base: Order, Implied Rules, and the Rules Everyone Forgets
A Check Point rule base is evaluated top to bottom, first match wins, and ends in an implicit drop that logs nothing. Two conventional rules exist to fix what that leaves you blind to, and knowing why they exist is more useful than knowing their names.
Security & WAFRead