cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted

What are to the point differences between Automatic & Manual NAT?

I'd like to know specific differences between automatic and manual NAT from interview point of view.

0 Kudos
5 Replies
Michal_Gans
Nickel

Re: What are to the point differences between Automatic & Manual NAT?

Automatic NAT is just 1:1 NAT, if you want something complex (like NAT based on dst port...), you need to use manual NAT.

0 Kudos

Re: What are to the point differences between Automatic & Manual NAT?

Automatic NATManual NAT
Rule automatically created by firewall.Rule manually created by administrator.
Cannot be modified.Can be modified.
Cannot create NO-NAT rule.Can create NO-NAT rule.
Cannot perform DUAL NATCan perform DUAL NAT.
Port forwarding not possible.Port forwarding is possible.
Proxy ARP is automatically created.Proxy ARP has to be manually created.

Let me know if any corrections are required Smiley Happy

Admin
Admin

Re: What are to the point differences between Automatic & Manual NAT?

Actually, your statement about dual NAT is at least partially incorrect.

There is a global property that controls whether or not two automatic NAT rules can match a connection called "Allow bi-direcitonal NAT."

That allows so-called dual NAT.

Re: What are to the point differences between Automatic & Manual NAT?

Automatic NAT - Cannot perform Dual NAT - Actually if "allow bi-directional NAT" is checked in the NAT global properties (it is set by default), two Automatic NAT rules can match the same packet and translate the source and destination IP address simultaneously.  They must both be Automatic rules and only one rule can match the source, and another different rule can only match the destination.  If this situation occurs you'll see a "NAT additional rule" field in your log.

Automatic NAT - Port Forwarding not Possible - Technically correct, but port forwarding operations can be performed in a mapped service such as http_mapped without using a manual NAT rule.

Manual NAT - Proxy ARP had to be manually created - By default that is correct, but see this feature you can potentially enable in R80.10 and later: sk114395: Automatic creation of Proxy ARP for Manual NAT rules on Security Gateway R80.10

--
"IPS Immersion Training" Self-paced Video Class
Now Available at http://www.maxpowerfirewalls.com

"IPS Immersion Training" Self-paced Video Class
Now Available at http://www.maxpowerfirewalls.com

Re: What are to the point differences between Automatic & Manual NAT?

Hello, take a look https://community.checkpoint.com/docs/DOC-3423?sr=inbox&ru=2138 

Regards.

Alessandro