nerdexam
Check_Point

156-215.80 · Question #188

MyCorp has the following NAT rules. You need to disable the NAT function when Alpha-internal networks try to reach the Google DNS (8.8.8.8) server. What can you do in this case?

The correct answer is D. Use network exception in the Alpha-internal network object. Check Point allows NAT to be selectively disabled for specific destination addresses by configuring a NAT exception directly within the source network object's properties.

Network Address Translation (NAT)

Question

MyCorp has the following NAT rules. You need to disable the NAT function when Alpha-internal networks try to reach the Google DNS (8.8.8.8) server. What can you do in this case?

Options

  • AUse manual NAT rule to make an exception
  • BUse the NAT settings in the Global Properties
  • CDisable NAT inside the VPN community
  • DUse network exception in the Alpha-internal network object

How the community answered

(14 responses)
  • A
    7% (1)
  • B
    14% (2)
  • D
    79% (11)

Why each option

Check Point allows NAT to be selectively disabled for specific destination addresses by configuring a NAT exception directly within the source network object's properties.

AUse manual NAT rule to make an exception

Manual NAT rules define explicit translation entries but cannot override or create exceptions to automatic NAT rules that are already matched; the network object exception method is the correct approach for suppressing automatic NAT for a specific destination.

BUse the NAT settings in the Global Properties

Global Properties NAT settings configure gateway-level behaviors such as IP pool NAT and merge of manual and automatic rules, but do not support specifying per-destination exceptions for individual network objects.

CDisable NAT inside the VPN community

Disabling NAT within a VPN community removes address translation only for traffic traversing that VPN tunnel, and would not affect standard internal-to-internet traffic destined for a public IP like 8.8.8.8.

DUse network exception in the Alpha-internal network objectCorrect

In Check Point, a network object that has automatic Hide NAT configured also exposes a NAT exception list where specific destination IP addresses can be excluded from translation. By adding 8.8.8.8 as an exception inside the Alpha-internal network object, traffic from that network destined for Google DNS will pass through the gateway without any address translation applied. This is the purpose-built mechanism for creating per-destination NAT exceptions without disrupting the broader NAT rule set.

Concept tested: Check Point NAT exception configuration in network objects

Source: https://sc1.checkpoint.com/documents/R77/CP_R77_Firewall_AdminGuide/html_frameset.htm

Topics

#NAT exception#network object#NAT rules#Manual NAT

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice