Which TWO of the following statements are correct regarding the order of NAT processing in a Check Point Security Policy?
Trap 1: Automatic NAT rules are processed after all Manual NAT rules.
Automatic NAT rules defined in network object properties are processed with higher priority than Manual NAT rules. This ensures that object-based NAT is consistently applied before any granular manual overrides defined in the NAT policy tab are taken into consideration by the kernel's NAT decision engine.
Trap 2: Automatic NAT is ignored if a Manual NAT rule matches.
Automatic NAT rules take precedence over Manual NAT rules. Even if a manual rule exists that could potentially match, the engine evaluates Automatic NAT first. This hierarchy is a fundamental design principle in Check Point gateways to maintain consistency for object-based address translation across the entire policy set.
Trap 3: Manual NAT rules are processed before Automatic NAT rules.
Manual NAT rules are always evaluated after Automatic NAT rules. The security gateway checks for any Automatic NAT configuration on the source and destination objects first. If a match is found, the translation occurs, and the manual NAT policy rules are not evaluated for that specific traffic session.
- A
Automatic NAT rules are processed after all Manual NAT rules.
Why it fails: Automatic NAT rules defined in network object properties are processed with higher priority than Manual NAT rules. This ensures that object-based NAT is consistently applied before any granular manual overrides defined in the NAT policy tab are taken into consideration by the kernel's NAT decision engine.
- B
Manual NAT rules are evaluated in a top-down order.
Manual NAT rules are evaluated sequentially from the top of the policy list to the bottom. The first rule that matches the traffic criteria determines the translation method. This necessitates careful rule ordering to prevent broader rules from shadowing more specific, narrow NAT requirements later in the policy.
- C
Automatic NAT is ignored if a Manual NAT rule matches.
Why it fails: Automatic NAT rules take precedence over Manual NAT rules. Even if a manual rule exists that could potentially match, the engine evaluates Automatic NAT first. This hierarchy is a fundamental design principle in Check Point gateways to maintain consistency for object-based address translation across the entire policy set.
- D
Manual NAT rules are processed before Automatic NAT rules.
Why it fails: Manual NAT rules are always evaluated after Automatic NAT rules. The security gateway checks for any Automatic NAT configuration on the source and destination objects first. If a match is found, the translation occurs, and the manual NAT policy rules are not evaluated for that specific traffic session.
- E
NAT rules are matched based on the first rule that meets the criteria.
Within the Manual NAT policy, the gateway applies the first rule that matches the traffic's source, destination, and service. Once a match is made, the evaluation stops, and the translation specified in that rule is applied to the packet, ensuring predictable and deterministic NAT behavior for administrators.