Be able to build and order NAT rules in SmartConsole, choose the correct NAT method per object, and verify translations on the gateway. The most important thing is getting rule order and NAT type right so traffic is translated as intended.
Start practicing
Security Policy and NAT — choose a session length
Free · No account required
Domain overview
This domain covers Check Point Security Policy configuration and Network Address Translation on R80. x gateways managed by SmartConsole. Candidates must configure NAT rules in the NAT Rule Base, apply them alongside firewall and security policy, and verify translations using gateway tools.
Questions test rule placement, NAT object settings, and real-time troubleshooting of translation behavior.
Exam objectives
Configuring Hide NAT and Static NAT in SmartConsole NAT Rule Base for internal and external traffic
Using fw monitor and fw ctl zdebug on the gateway to inspect live NAT translations
Setting NAT tabs on network and host objects, including automatic and manual NAT rules
Understanding NAT rule ordering, original versus translated packets, and bidirectional translation
Assuming Automatic NAT rules always take precedence; manual NAT rules can override, and rule order determines which translation applies first.
Forgetting that NAT is enforced on the gateway, so policy installation and gateway selection must be correct for the rule to take effect.
Confusing Hide NAT with Static NAT for inbound access; Hide NAT cannot accept unsolicited inbound connections to internal hosts.
Click any question to see the full explanation and answer options, or start a focused practice session above.
An administrator needs to ensure that traffic from the internal network (10.10.10.0/24) accessing the Internet is translated to the gateway's external interface IP. Which NAT configuration method is required to achieve this while ensuring that the internal IP addresses are never exposed to the Internet?
2Refer to the exhibit. An administrator notices that traffic intended for a NAT rule is being dropped because the destination interface is being incorrectly evaluated. Given the current kernel parameter setting, what does this indicate regarding NAT policy processing?
3Where do you configure 'Automatic NAT' for a specific network host object in SmartConsole?
4Which THREE of the following are valid methods or configurations associated with NAT in Check Point?
5Which command is most useful for troubleshooting NAT issues on a Check Point Security Gateway to see the actual translation occurring in real-time?
6Why might you use a 'Hide NAT' rule with a specific IP pool instead of a single interface IP?
7Which object property must be enabled on a gateway for it to support NAT?
8Refer to the exhibit. An administrator notices that traffic from Internal_Net to Server_Farm is being translated by Rule 1 instead of Rule 2. What is the most likely cause?
9An administrator is configuring Static NAT for a server. Which NAT option should be selected in the object properties to ensure that the server is reachable via a dedicated public IP address, allowing both inbound and outbound traffic?
10Which of these is the primary benefit of using manual NAT rules in a large, complex network?
11Refer to the exhibit. An administrator is experiencing intermittent connectivity issues for users behind Hide NAT. What might this setting indicate regarding the root cause?
12When configuring a NAT rule that involves a VPN community, why is 'Hide NAT' often problematic?
13Which TWO of the following are consequences of using 'Hide NAT' incorrectly in a network environment?
14A security administrator at a company with a Check Point R81 management server and two clustered Security Gateways is configuring NAT for a web server on the internal network. The server's private IP is 192.168.10.50, and it must be reachable from the Internet at public IP 203.0.113.25. The administrator wants to ensure that return traffic from the server is automatically translated back to the public IP without creating a separate outbound NAT rule. Which NAT method should be configured on the web server object in SmartConsole?
15A company uses Hide NAT to allow internal users to access the Internet through a single public IP address on the gateway. The security administrator notices that external servers cannot initiate connections to internal hosts, but internal users can reach external services. Which statement explains why external servers cannot initiate connections to internal hosts in this scenario?
16A security administrator is troubleshooting a NAT configuration on a Check Point Security Gateway. Internal users cannot reach an external web server through a manual Hide NAT rule, although the Security Policy allows the traffic. The administrator suspects that the NAT rule is not being applied. Which two actions should the administrator take to verify that NAT translation is occurring as expected? (Choose two.)
17A security administrator is configuring NAT for a new internal server (10.0.0.5) that needs to be accessible from the Internet on port 443 using the public IP 203.0.113.20. The administrator creates a host object for the server and configures a Static NAT rule. Which additional configuration is required to allow inbound HTTPS traffic to reach the server?
18An administrator is configuring NAT on a Check Point R81 Security Gateway. A web server with a private IP address of 10.1.1.10 must be reachable from the Internet at the public IP address 203.0.113.10. The administrator creates a host object for the web server and configures a Static NAT rule. Which translation method should be selected in the NAT rule so that the internal IP address is translated to the public IP address?
19A security administrator is configuring a NAT rule to hide internal users behind the gateway's external IP when accessing the Internet. The administrator wants to ensure that return traffic is correctly routed back to the internal users. Which configuration setting is essential for this to work?
20An administrator is reviewing the NAT configuration on a Check Point R81 Security Gateway. The gateway has two interfaces: eth1 (internal, 192.168.1.1) and eth2 (external, 203.0.113.1). Internal users need to access the Internet, and the administrator wants to hide their private IP addresses behind the external interface IP. The administrator creates a Hide NAT rule for the internal network object. Which statement correctly describes the outcome of this configuration?
21An administrator is configuring NAT for a new web server on the internal network. The server must be accessible from the Internet using a public IP address, and connections must be initiated from the Internet to the server. The internal IP is 10.1.1.10, and the public IP is 203.0.113.10. Which NAT method should be used?
22A Check Point administrator is configuring NAT for a new subnet that will be used for a guest wireless network. The guest subnet is 172.16.50.0/24, and the administrator wants to hide all guest traffic behind the external interface IP 203.0.113.5. The administrator creates a network object for the guest subnet and configures Hide NAT using the external interface. After testing, guests can access the Internet, but the administrator notices that the translation is not being applied to traffic originating from the guest subnet when it is destined to a server on the internal network (192.168.1.0/24). What is the most likely reason for this behavior?
23A security administrator is configuring NAT for a network where internal users need to access external web servers. The administrator wants to hide the internal IP addresses behind a single public IP address. However, some internal users report that they cannot access certain websites that require multiple simultaneous connections from the same source IP. What is the most likely cause of this issue?
24A security administrator is configuring NAT for a Check Point R81 Security Gateway that protects a web server farm. The administrator needs to ensure that external users can access the web servers using a single public IP, and that the web servers can initiate outbound connections to the Internet. The administrator decides to use manual NAT rules. Which two statements are correct regarding the configuration of manual NAT rules in this scenario? (Choose two.)
25An administrator needs to allow internal users to access the Internet using Hide NAT. The internal network is 192.168.1.0/24, and the gateway's external interface IP is 203.0.113.5. Which NAT rule should be configured?
26A security administrator is configuring NAT for a Check Point R81 Security Gateway that protects a DMZ. The DMZ contains a mail server with IP address 10.10.10.5 and a web server with IP address 10.10.10.6. Both servers must be accessible from the Internet using separate public IP addresses. The administrator wants to minimize the number of NAT rules and ensure that the translation is applied correctly. Which NAT configuration approach is most appropriate?
Be able to build and order NAT rules in SmartConsole, choose the correct NAT method per object, and verify translations on the gateway. The most important thing is getting rule order and NAT type right so traffic is translated as intended.
The Courseiva 156-215.81.20 question bank contains 26 questions in the Security Policy and NAT domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security Policy and NAT domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included