ExamGecko
Question list
Search
Search

Question 612 - 156-315.81 discussion

Report
Export

Which of the following is true regarding the Proxy ARP feature for Manual NAT?

A.
The local.arp file must always be configured
Answers
A.
The local.arp file must always be configured
B.
Automatic proxy ARP configuration can be enabled
Answers
B.
Automatic proxy ARP configuration can be enabled
C.
fw ctl proxy should be configured
Answers
C.
fw ctl proxy should be configured
D.
Translate Destination on Client Side should be configured
Answers
D.
Translate Destination on Client Side should be configured
Suggested answer: B

Explanation:

The verified answer is B) Automatic proxy ARP configuration can be enabled.

Proxy ARP is a feature that allows a gateway to respond to ARP requests on behalf of another IP address that is not on the same network segment. Proxy ARP is required for manual NAT rules when the NATed IP addresses are not routed to the gateway1.

By default, proxy ARP for manual NAT rules has to be configured manually by editing the local.arp file or using the CLISH commands on the gateway2. However, since R80.10, there is an option to enable automatic proxy ARP configuration for manual NAT rules by modifying the files $CPDIR/tmp/.CPprofile.sh and $CPDIR/tmp/.CPprofile.csh on the gateway3.

fw ctl proxy is a command that displays the proxy ARP table on the gateway, but it does not configure proxy ARP4.

Translate Destination on Client Side is a NAT option that determines whether the destination IP address is translated before or after the routing decision. It does not affect proxy ARP.

Configuring Proxy ARP for Manual NAT - Check Point Software1

R80.10: Automatic Proxy ARP with Manual NAT rules - checkpoint<dot>engineer2

Automatic creation of Proxy ARP for Manual NAT rules on Security Gateway R80.103

fw ctl proxy - Check Point Software

NAT Properties - Check Point Software

asked 16/09/2024
junjie wang
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first