Nat Flashcards

1
Q

What are the two ways to configure NAT?

A

Central NAT or FW policy NAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When do you use FW policy NAT

A

Firewall policy NAT is suggested for deployments that include relatively few NAT IP addresses and where each NAT IP address would have separate policies and security profiles.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When should you use central NAT

A

Central NAT is suggested for more complex scenarios where multiple NAT IP addresses have identical policies and security profiles, or in next generation firewall (NGFW) policy mode, where the appropriate policy may not be determined at the first packet.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

two ways to configure firewall policy SNAT

A

• Use the outgoing interface address.

• Use the dynamic IP pool

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

IP pool

A

defines a single IP address or a range of IP addresses to be used as the source address for the duration of the session.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

four types of IP pools

A

Overload
• One-to-one
Fixed port range CGN
• Port block allocation CGN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

overload IP pool type

A

a many-to-one or many-to-few relationship and port translation is used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

one-to-one pool type

A

FortiGate assigns an IP pool address to an internal host on a first-come, firstserved basis.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Where do you enable DNAT?

A

You use a a VIP object on FW policy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

CGN IP pool type fixed port range

A

Ability to identify the subscribe of a connection by public ip add and port (no traffic log required)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Port block allocation - Ip pool type

A

You define the ip add, block port size and number of blocks assigned to each host. Logs each new system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the default VIP type?

A

Static NAT; one to one

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Port Forwarding on VIP

A

redirect the traffic matching the external address and port in the VIP to the mapped internal address and port. When you enable port forwarding, FortiGate no longer performs one-to-one mapping.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

if the VIP is not referenced in an incoming firewall policy, or the policy is disabled, what happens?

A

It uses the external int ip add

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Do VIPs match on FW policies?

A

No.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is ARP reply?

A

Instructs FG to reply to ARP requests for external addresses, overcomes routing misconfigs, on by default

17
Q

Central SNAT is mandatory for the new NGFW policy-based mode?

A

Yes

18
Q

For central DNAT; instead of referencing the VIP, you reference the mapped internal address as destination in the firewall, and not the external address, why?

A

This is because for ingress traffic, DNAT takes place before the firewall policy lookup. That is, FortiGate considers the translated destination address during the firewall policy lookup process.

19
Q

True or false: you don’t need to schedule a maintenance window to switch NAT modes

A

False