View Single Post
  #1 (permalink)  
Old 2006-01-02
Sergej Sergej is offline
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default qestion for exam: Bidirectional NAT theory

Hi, I'm studing for recertification. Colege pass me that there are a lot of misterious qestions about NAT. I want to be cool in CheckPoint NAT aspects and terminology. I'm using oficial courseware (b.llsh.t) + Help files (I prefere .hlp files, becouse they are the same as PDF but easy navigation and better screenshots).

Here is a qestions about Manual vs Automatic NAT.

Accoding to "Check Point Solution for Network Address Translation" > "Bidirectional NAT" it is possible to mach and translate bouth sourse and destination addreses with automalic rures:
With Bidirectional NAT, both automatic NAT rules are applied, and both objects will be translated, so connections between the two objects will be allowed in both directions.

The detailed logic of Bidirectional NAT is as follows:

If the first match on a connection is on an Automatic NAT rule, then the rest of the NAT Rule Base is checked, one rule at a time, to see if another Automatic NAT Rule matches the connection. If it does, both rules are matched, and no further checking is performed.
According to "Planning Considerations for NAT" > "Automatic Versus Manual Rules" translation of bouth source and destination addreses are exclusive feature of Manual NAT:

The following can only be done using Manual NAT Rules:

Translating both source and destination IP addresses in the same packet.
There are two conflcting statemlents. Which one is correct?

Last edited by Sergej; 2006-01-02 at 05:13.
Reply With Quote