156-215.80 · Question #383
What needs to be configured if the NAT property `Translate destination on client side' is not enabled in Global properties?
The correct answer is C. Nothing, the Gateway takes care of all details necessary. When 'Translate destination on client side' is disabled in Check Point Global Properties, no additional manual configuration is needed because the Security Gateway automatically handles all NAT translation details.
Question
What needs to be configured if the NAT property `Translate destination on client side' is not enabled in Global properties?
Options
- AA host route to route to the destination IP
- BUse the file local.arp to add the ARP entries for NAT to work
- CNothing, the Gateway takes care of all details necessary
- DEnabling `Allow bi-directional NAT' for NAT to work correctly
How the community answered
(40 responses)- A13% (5)
- B8% (3)
- C78% (31)
- D3% (1)
Why each option
When 'Translate destination on client side' is disabled in Check Point Global Properties, no additional manual configuration is needed because the Security Gateway automatically handles all NAT translation details.
A manual host route is not required because the Security Gateway automatically handles routing for NAT-translated addresses without administrator-added static routes.
Manually adding ARP entries via local.arp is only necessary in specific edge cases where automatic ARP is not functioning, not as a general requirement when this property is disabled.
When 'Translate destination on client side' is not enabled, the Security Gateway performs destination NAT on the server side by default and automatically manages the associated ARP and routing details without any additional administrator configuration. Check Point's automatic NAT mechanism handles these tasks transparently as part of the gateway's built-in NAT functionality.
Bi-directional NAT is an independent feature that allows two NAT rules to match a connection simultaneously and has no dependency on the 'Translate destination on client side' setting.
Concept tested: Check Point NAT Global Properties automatic handling
Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Firewall_AdminGuide/Topics-FWG/NAT-Global-Properties.htm
Topics
Community Discussion
No community discussion yet for this question.