Hi all,
I'm reading a CCSA r80 manual and got stuck on some information about a Global Properties option that allows admins to choose between "Client side NAT" and "Server side NAT" and it breaks my mind. There's a lot of explaining where destination NAT happens within a Checkpoint GW ... just for confirmation it's before 3 by default isn't it? So that the OS can route it... right ?
( Correct me if I'm wrong )
1) i
2) I
Destination NAT to internal IP
3) OS routing
4)o
5)O
But do these client-side/server-side NAT options influence what IP address you need to use in the rule-base then ? ( use translated IP vs original IP's )
( I guess not )
And secondly, I do read in the documentation it influences routing.
- ( automatic NAT, no issues )
- ( manual NAT, possible manual routing needed )
But then I fail to image a real world scenario where this option would come in handy ? ( either for automatic/manual NAT rules )
Can someone explain in simple words a real world example why you would want this option server side ?
Thx a lot.