156-215.80 · Question #188
MyCorp has the following NAT rules. You need to disable the NAT function when Alpha-internal networks try to reach the Google DNS (8.8.8.8) server. What can you do in this case?
The correct answer is D. Use network exception in the Alpha-internal network object. Check Point allows NAT to be selectively disabled for specific destination addresses by configuring a NAT exception directly within the source network object's properties.
Question
MyCorp has the following NAT rules. You need to disable the NAT function when Alpha-internal networks try to reach the Google DNS (8.8.8.8) server. What can you do in this case?
Options
- AUse manual NAT rule to make an exception
- BUse the NAT settings in the Global Properties
- CDisable NAT inside the VPN community
- DUse network exception in the Alpha-internal network object
How the community answered
(14 responses)- A7% (1)
- B14% (2)
- D79% (11)
Why each option
Check Point allows NAT to be selectively disabled for specific destination addresses by configuring a NAT exception directly within the source network object's properties.
Manual NAT rules define explicit translation entries but cannot override or create exceptions to automatic NAT rules that are already matched; the network object exception method is the correct approach for suppressing automatic NAT for a specific destination.
Global Properties NAT settings configure gateway-level behaviors such as IP pool NAT and merge of manual and automatic rules, but do not support specifying per-destination exceptions for individual network objects.
Disabling NAT within a VPN community removes address translation only for traffic traversing that VPN tunnel, and would not affect standard internal-to-internet traffic destined for a public IP like 8.8.8.8.
In Check Point, a network object that has automatic Hide NAT configured also exposes a NAT exception list where specific destination IP addresses can be excluded from translation. By adding 8.8.8.8 as an exception inside the Alpha-internal network object, traffic from that network destined for Google DNS will pass through the gateway without any address translation applied. This is the purpose-built mechanism for creating per-destination NAT exceptions without disrupting the broader NAT rule set.
Concept tested: Check Point NAT exception configuration in network objects
Source: https://sc1.checkpoint.com/documents/R77/CP_R77_Firewall_AdminGuide/html_frameset.htm
Topics
Community Discussion
No community discussion yet for this question.