NAT Flashcards

1
Q

What is another term for Dynamic NAT?

A

IP masquerading

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which NAT changes the source IP address of each outgoing connection to match the Firebox’s IP address?

A

Dynamic NAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does Firebox track when using Dynamic NAT?

A
  1. Private Source & Dest. IP
  2. Source & Dest. Ports
  3. Protocols
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Enumarate examples (3) of IP header information

A
  1. Source port
  2. Destination port
  3. Protocols
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which NAT enables clients on a private network to connect to servers on the internet?

A

Dynamic NAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In Dynamic NAT, how many IP addresses does the internet see?

A

One (1)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In Dynamic NAT, what is the only IP address does the internet see?

A

Public IP address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

On which connnections is Dynamic NAT normally applied to?

A

Connections starting from behind a Firebox

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In Dynamic NAT, is the source port changed?

A

Only if necessary.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

In Dynamic NAT, how often does the Firebox keep the same source port that the requesting client use?

A

Always.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which NAT is configured as default on Firebox?

A

Dynamic NAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

On which kinds of IP addresses is Dynamic NAT applied on by default?

A

RFC1918

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

In Policy Manager, how to configure Dynamic NAT rules?

A

Network tab > NAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Is Dynamic NAT enabled by default on each policy you create?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Can you override the global dynamic NAT settings in individual policies?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What can be used to override the global dynamic NAT settings?

A

Individual policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

In Dynamic NAT, which IP address of the external interface does is used when traffic leaves?

A

Primary IP address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Enumerate two (2) procedures on setting the Dynamic NAT source IP address.

A
  1. Network Dynamic NAT rule
  2. Policy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is another term for Static NAT?

A

Port forwarding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Which NAT allows inbound connections on the specific ports to one or more public servers from a single external IP address?

A

Static NAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

In Static NAT, what does the Firebox change?

A

Destination IP address of the packets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

In Static NAT, what is the basis of the Firebox when forwarding packets?

A

Based on the original destination port number

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is Static NAT typically used for?

A

Public services such as websites and email

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Which NAT is recommended if you have a small number of public IP addresses

A

Static NAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Which NAT is the only option if you have only one public IP address?
Static NAT
26
What is the default behavior of Static NAT?
Does not change the source IP address for inbound traffic
27
In Static NAT, which IP address is not changed by default?
Source IP address
28
Where is the static NAT configuration saved when you configure a Static NAT?
SNAT action
29
Can you add, edit, or delete SNAT actions?
Yes
30
What can you do to the SNAT action after creating it?
Can you the same action in one or more policies.
31
What are the two (2) types of SNAT actions?
1. Static NAT 2. Server Load Balancing
32
What kind of traffic does the Static NAT forward?
Inbound traffic
33
In addition to an IP address, what can you specify in an SNAT action?
FQDN
34
Which SNAT action forwards inbound traffic addressed to one IP address to one of several servers behind the firewall?
Server Load Balancing
35
Which SNAT action forwards inbound traffic addressed to one IP address to a different IP address and port behind the firewall?
Static NAT
36
In a static NAT action, where is inbound traffic addressed to one IP address forwarded to?
To a different IP address and port
37
In a server load balancing, where is inbound traffic addressed to one IP address forwarded to?
To one of several servers
38
What section do you add the SNAT action?
To section
39
Which NAT provides a mapping for one or more private IP addresses to one or more public IP addresses?
1-to-1 NAT
40
Which NAT allows the internal network resources accessible on the internet?
1-to-1 NAT
41
Which NAT is for networks with many public IP addresses?
1-to-1 NAT
42
Which NAT is an OPTION if you want to dedicate a public IP address for a single purpose?
1-to-1 NAT
43
Is it recommended to use 1-to-1 NAT rather than SNAT?
No. SNAT is better.
44
In 1-to-1 NAT, what is prevented is you only have 1 public IP?
All use of inbound Firebox functions
45
In 1-to-1 NAT, can the WatchGuard Support team connect with only having 1 public IP?
No.
46
What can you configure in each 1-to-1 NAT rule?
1. Host 2. Range of hosts 3. Subnet
47
Which NAT rule always has a precedence over Dynamic NAT?
1-to-1 NAT
48
What do you need to specify for each 1-to-1 NAT rule?
1. Interface 2. Real base 3. NAT base 4. Number of hosts to NAT (for ranges only)
49
What do you call the thing on which 1-to-1 NAT is to be applied?
Interface
50
What do you call the IP address assigned to the physical Ethernet interface of the computer to which you apply the 1-to-1 NAT policy?
Real base
51
What do you call the base where the private addresses are used?
Real base
52
What do you call the IP address that the real base IP address changes to whne 1-to-1 NAT is applied?
NAT base
53
What do you call the base where the public addresses are used?
NAT base
54
What do you use when local network users need to connect to an internal server with the public IP address or domain name of that server?
NAT loopback
55
In dynamic NAT, what IP address gets changed?
Source IP
56
Which NAT is often used for outbound traffic?
Dynamic NAT
57
Which NAT is the most common NAT?
Dynamic NAT
58
Which VPN is DNAT available for?
BOVPN
59
In Static NAT, what IP address gets changed?
Destination IP
60
Which NAT is often used for inbound traffic?
Static NAT
61
On which NAT can SNAT be combined with?
DNAT
62
Which NAT allows you to configure 1 public IP to multiple servers?
Static NAT
63
Since you can configure 1 public IP to multiple servers, how can the traffic be differentiated?
Different ports
64
Which NAT maps 1 subnet to another subnet, or binds 1 IP to another IP?
1-to-1 NAT
65
Which IP is changed for 1-to-1 NAT?
Source and Destination IP
66
What is also known as HAIRPIN NAT?
NAT Loopback
67
What NATs are used with NAT Loopback?
SNAT & 1-to-1 NAT
68
Which NAT allows local clients to communicate to a public IP that points to a local server?
1-to-1 NAT
69
When is NAT loopback useful?
When DNS records points only at a public IP
70
How do you configure SNAT in policy manager?
Setup tab > Actions > SNAT