nerdexam
Check_Point

156-215.80 · Question #383

What needs to be configured if the NAT property `Translate destination on client side' is not enabled in Global properties?

The correct answer is C. Nothing, the Gateway takes care of all details necessary. When 'Translate destination on client side' is disabled in Check Point Global Properties, no additional manual configuration is needed because the Security Gateway automatically handles all NAT translation details.

Network Address Translation (NAT)

Question

What needs to be configured if the NAT property `Translate destination on client side' is not enabled in Global properties?

Options

  • AA host route to route to the destination IP
  • BUse the file local.arp to add the ARP entries for NAT to work
  • CNothing, the Gateway takes care of all details necessary
  • DEnabling `Allow bi-directional NAT' for NAT to work correctly

How the community answered

(40 responses)
  • A
    13% (5)
  • B
    8% (3)
  • C
    78% (31)
  • D
    3% (1)

Why each option

When 'Translate destination on client side' is disabled in Check Point Global Properties, no additional manual configuration is needed because the Security Gateway automatically handles all NAT translation details.

AA host route to route to the destination IP

A manual host route is not required because the Security Gateway automatically handles routing for NAT-translated addresses without administrator-added static routes.

BUse the file local.arp to add the ARP entries for NAT to work

Manually adding ARP entries via local.arp is only necessary in specific edge cases where automatic ARP is not functioning, not as a general requirement when this property is disabled.

CNothing, the Gateway takes care of all details necessaryCorrect

When 'Translate destination on client side' is not enabled, the Security Gateway performs destination NAT on the server side by default and automatically manages the associated ARP and routing details without any additional administrator configuration. Check Point's automatic NAT mechanism handles these tasks transparently as part of the gateway's built-in NAT functionality.

DEnabling `Allow bi-directional NAT' for NAT to work correctly

Bi-directional NAT is an independent feature that allows two NAT rules to match a connection simultaneously and has no dependency on the 'Translate destination on client side' setting.

Concept tested: Check Point NAT Global Properties automatic handling

Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Firewall_AdminGuide/Topics-FWG/NAT-Global-Properties.htm

Topics

#translate destination client side#NAT global properties#ARP#automatic NAT

Community Discussion

No community discussion yet for this question.

Full 156-215.80 Practice