Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Fincher
Participant

Allow bi-directional NAT

Jump to solution

Hi all!

 

How i can setting's "Allow bi-directional NAT" on the each Gateway?

 

Or i can setting "Allow bi-directional NAT" only in Global Properties?

 

Thanks for help!

0 Kudos
1 Solution

Accepted Solutions
_Val_
Admin
Admin

This is a third party guide, and yes, on the page 112 the remediation step for NAT is incorrect. 

This is how it looks in SmartConsole: 

Screenshot 2022-01-19 at 14.32.10.png

So the Remediation Steps should be:

SmartConsole / Menu / Global Properties / NAT - Network Address Translation / bla-bla


View solution in original post

0 Kudos
6 Replies
_Val_
Admin
Admin

Global Properties only. Why?

0 Kudos
Fincher
Participant

Because we have CIS - CheckPoint firewall benchmark, and in this document we have this requirment:

Remediation:
Go to the following path and Configured the Allow bi-directional NAT.
SmartConsole -> Gateways & Servers -> select each Gateway -> NAT Network Address Translation -> Unchecked the Allow bi-directional NAT
 
I attach this file.
 
Requirment 3.18 Ensure Allow bi-directional NAT is enabled (Automated)
0 Kudos
_Val_
Admin
Admin

The document says, bi-directional NAT should be enabled.

It is actually already enabled by default in Global Properties. So I am asking again, what exactly are you trying to achieve here? Check it is indeed the case? Or something else?

0 Kudos
Fincher
Participant

I'm trying to figure out how to properly set up bi-directional NAT. Because the remediation says to enable bi-directional NAT on each gateway. But this setting is not in the NAT settings on the gateways. It turns out the document gives false information?

0 Kudos
_Val_
Admin
Admin

This is a third party guide, and yes, on the page 112 the remediation step for NAT is incorrect. 

This is how it looks in SmartConsole: 

Screenshot 2022-01-19 at 14.32.10.png

So the Remediation Steps should be:

SmartConsole / Menu / Global Properties / NAT - Network Address Translation / bla-bla


0 Kudos
Fincher
Participant

Thanks a lot!

0 Kudos