nerdexam
Check_Point

156-815.70 · Question #68

To increase the security of your NOC, you decide to install a NOC firewall and hire a firewall expert to manage it. The firewall expert wants to hide all of the invalid IP addresses of the CMAs, by…

The correct answer is B. No, because Hide NAT does not allow remote Gateways to connect directly to the CMAs. See the full explanation below for the reasoning.

Question

To increase the security of your NOC, you decide to install a NOC firewall and hire a firewall expert to manage it. The firewall expert wants to hide all of the invalid IP addresses of the CMAs, by installing a Hide NAT Policy on the firewall. Will this plan work?

Options

  • ANo, because VPN-1 NGX does not allow Administrators to configure Hide NAT on objects with
  • BNo, because Hide NAT does not allow remote Gateways to connect directly to the CMAs.
  • CYes, but only if Hide NAT is configured with the Hide address of the leading MDS interface.
  • DYes, because the CMAs use virtual IP addresses, and they require a single valid IP address to

How the community answered

(20 responses)
  • B
    85% (17)
  • C
    5% (1)
  • D
    10% (2)

Community Discussion

No community discussion yet for this question.

Full 156-815.70 Practice