nerdexam
Check_Point

156-215.76 · Question #130

You are a Security Administrator who has installed Security Gateway R76 on your network. You need to allow a specific IP address range for a partner site to access your intranet Web server. To limit…

The correct answer is D. No. The first setting is only applicable to automatic NAT rules. The second setting will force translation. See the full explanation below for the reasoning.

Question

You are a Security Administrator who has installed Security Gateway R76 on your network. You need to allow a specific IP address range for a partner site to access your intranet Web server. To limit the partner's access for HTTP and FTP only, you did the following:

(1) Created manual Static NAT rules for the Web server. (2) Cleared the following settings in the Global Properties > Network Address Translation screen:

  • Allow bi-directional NAT
  • Translate destination on client side

Do the above settings limit the partner's access?

Options

  • ANo. The first setting is not applicable. The second setting will reduce performance.
  • BYes. This will ensure that traffic only matches the specific rule configured for this traffic, and that the
  • CYes. Both of these settings are only applicable to automatic NAT rules.
  • DNo. The first setting is only applicable to automatic NAT rules. The second setting will force translation

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    8% (3)
  • C
    15% (6)
  • D
    72% (28)

Community Discussion

No community discussion yet for this question.

Full 156-215.76 Practice