NAT Flashcards
What is another term for Dynamic NAT?
IP masquerading
Which NAT changes the source IP address of each outgoing connection to match the Firebox’s IP address?
Dynamic NAT
What does Firebox track when using Dynamic NAT?
- Private Source & Dest. IP
- Source & Dest. Ports
- Protocols
Enumarate examples (3) of IP header information
- Source port
- Destination port
- Protocols
Which NAT enables clients on a private network to connect to servers on the internet?
Dynamic NAT
In Dynamic NAT, how many IP addresses does the internet see?
One (1)
In Dynamic NAT, what is the only IP address does the internet see?
Public IP address
On which connnections is Dynamic NAT normally applied to?
Connections starting from behind a Firebox
In Dynamic NAT, is the source port changed?
Only if necessary.
In Dynamic NAT, how often does the Firebox keep the same source port that the requesting client use?
Always.
Which NAT is configured as default on Firebox?
Dynamic NAT
On which kinds of IP addresses is Dynamic NAT applied on by default?
RFC1918
In Policy Manager, how to configure Dynamic NAT rules?
Network tab > NAT
Is Dynamic NAT enabled by default on each policy you create?
Yes
Can you override the global dynamic NAT settings in individual policies?
Yes
What can be used to override the global dynamic NAT settings?
Individual policies
In Dynamic NAT, which IP address of the external interface does is used when traffic leaves?
Primary IP address
Enumerate two (2) procedures on setting the Dynamic NAT source IP address.
- Network Dynamic NAT rule
- Policy
What is another term for Static NAT?
Port forwarding
Which NAT allows inbound connections on the specific ports to one or more public servers from a single external IP address?
Static NAT
In Static NAT, what does the Firebox change?
Destination IP address of the packets
In Static NAT, what is the basis of the Firebox when forwarding packets?
Based on the original destination port number
What is Static NAT typically used for?
Public services such as websites and email
Which NAT is recommended if you have a small number of public IP addresses
Static NAT
Which NAT is the only option if you have only one public IP address?
Static NAT
What is the default behavior of Static NAT?
Does not change the source IP address for inbound traffic
In Static NAT, which IP address is not changed by default?
Source IP address
Where is the static NAT configuration saved when you configure a Static NAT?
SNAT action