- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I'd like to know specific differences between automatic and manual NAT from interview point of view.
Automatic NAT is just 1:1 NAT, if you want something complex (like NAT based on dst port...), you need to use manual NAT.
| Automatic NAT | Manual NAT |
|---|---|
| Rule automatically created by firewall. | Rule manually created by administrator. |
| Cannot be modified. | Can be modified. |
| Cannot create NO-NAT rule. | Can create NO-NAT rule. |
| Cannot perform DUAL NAT | Can perform DUAL NAT. |
| Port forwarding not possible. | Port forwarding is possible. |
| Proxy ARP is automatically created. | Proxy ARP has to be manually created. |
Let me know if any corrections are required ![]()
Actually, your statement about dual NAT is at least partially incorrect.
There is a global property that controls whether or not two automatic NAT rules can match a connection called "Allow bi-direcitonal NAT."
That allows so-called dual NAT.
Automatic NAT - Cannot perform Dual NAT - Actually if "allow bi-directional NAT" is checked in the NAT global properties (it is set by default), two Automatic NAT rules can match the same packet and translate the source and destination IP address simultaneously. They must both be Automatic rules and only one rule can match the source, and another different rule can only match the destination. If this situation occurs you'll see a "NAT additional rule" field in your log.
Automatic NAT - Port Forwarding not Possible - Technically correct, but port forwarding operations can be performed in a mapped service such as http_mapped without using a manual NAT rule.
Manual NAT - Proxy ARP had to be manually created - By default that is correct, but see this feature you can potentially enable in R80.10 and later: sk114395: Automatic creation of Proxy ARP for Manual NAT rules on Security Gateway R80.10
--
"IPS Immersion Training" Self-paced Video Class
Now Available at http://www.maxpowerfirewalls.com
Hello, take a look https://community.checkpoint.com/docs/DOC-3423?sr=inbox&ru=2138
Regards.
Alessandro
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY