Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Rohit_Gandas
Participant

What are to the point differences between Automatic & Manual NAT?

I'd like to know specific differences between automatic and manual NAT from interview point of view.

0 Kudos
5 Replies
Michal_Gans
Contributor
Contributor

Automatic NAT is just 1:1 NAT, if you want something complex (like NAT based on dst port...), you need to use manual NAT.

0 Kudos
Rohit_Gandas
Participant

Automatic NATManual NAT
Rule automatically created by firewall.Rule manually created by administrator.
Cannot be modified.Can be modified.
Cannot create NO-NAT rule.Can create NO-NAT rule.
Cannot perform DUAL NATCan perform DUAL NAT.
Port forwarding not possible.Port forwarding is possible.
Proxy ARP is automatically created.Proxy ARP has to be manually created.

Let me know if any corrections are required Smiley Happy

PhoneBoy
Admin
Admin

Actually, your statement about dual NAT is at least partially incorrect.

There is a global property that controls whether or not two automatic NAT rules can match a connection called "Allow bi-direcitonal NAT."

That allows so-called dual NAT.

Timothy_Hall
Legend Legend
Legend

Automatic NAT - Cannot perform Dual NAT - Actually if "allow bi-directional NAT" is checked in the NAT global properties (it is set by default), two Automatic NAT rules can match the same packet and translate the source and destination IP address simultaneously.  They must both be Automatic rules and only one rule can match the source, and another different rule can only match the destination.  If this situation occurs you'll see a "NAT additional rule" field in your log.

Automatic NAT - Port Forwarding not Possible - Technically correct, but port forwarding operations can be performed in a mapped service such as http_mapped without using a manual NAT rule.

Manual NAT - Proxy ARP had to be manually created - By default that is correct, but see this feature you can potentially enable in R80.10 and later: sk114395: Automatic creation of Proxy ARP for Manual NAT rules on Security Gateway R80.10

--
"IPS Immersion Training" Self-paced Video Class
Now Available at http://www.maxpowerfirewalls.com

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
Alessandro_Marr
Advisor

Hello, take a look https://community.checkpoint.com/docs/DOC-3423?sr=inbox&ru=2138 

Regards.

Alessandro

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events