Which of the following is NOT supported by Bridge Mode Check Point Security Gateway?
Which of the following is NOT supported by Bridge Mode Check Point Security Gateway?
Bridge mode on Check Point Security Gateway does not support Network Address Translation (NAT). NAT is used to modify network address information in packet headers, a function that is not compatible with the transparent nature of bridge mode, which operates at the data link layer (Layer 2). Bridge mode focuses on packet filtering and security without altering the packet's IP addresses, therefore features dependent on IP manipulation like NAT are not supported.
Yes, NAT: Limitations in Bridge Mode You can configure only two slave interfaces in a single Bridge interface. You can think of this Bridge interface as a two-port Layer 2 switch. Each port can be a Physical interface, a VLAN interface, or a Bond interface. These features and deployments are not supported in Bridge Mode: Assigning an IP address to a Bridge interface in ClusterXL. NAT rules (specifically, FireWall kernel in logs shows the traffic as accepted, but Security Gateway does not actually forward it). For more information, see sk106146. Access to Multi-Portal (Mobile Access Portal, Identity Awareness Captive Portal, Data Loss Prevention Portal, and so on) from bridged networks, if the bridge does not have an assigned IP address. Clusters with more than two Cluster Members. Full High Availability Cluster. Asymmetric traffic inspection in ClusterXL in Active/Active Bridge Mode. (Asymmetric traffic inspection is any situation, where the Client-to-Server packet is inspected by one Cluster Member, while the Server-to-Client packet is inspected by the other Cluster Member. In such scenarios, several security features do not work.)
agree (Limitations in Bridge Mode) https://sc1.checkpoint.com/documents/R80.20SP/WebAdminGuides/EN/CP_R80.20SP_Maestro_AdminGuide/Topics-Maestro-AG/Bridge-Mode-Security-Group.htm https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Installation_and_Upgrade_Guide/Topics-IUG/Deploying-Security-Gateway-or-ClusterXL-in-Bridge-Mode.htm
Yes NAT