The correct answer isD. Translating services, meaning destination-port translation, is a use case forManual NAT rules. Check Point’s Security Management documentation lists “Translating services (destination ports)” as one of the scenarios where administrators must manually define NAT rules. Automatic NAT is useful for common static or hide translation on network objects, but it is not designed to express every packet-level translation condition, especially when the translated service/port itself must be changed. Option A is wrong because “Translate Destination on Server Side” is an automatic NAT behavior setting, not the complete mechanism for service translation. Option B is wrong because Bi-Directional NAT is about automatically creating reverse translation behavior, not destination-port translation. Option C is wrong because Automatic ARP Configuration deals with ARP behavior for translated addresses, not TCP/UDP service rewriting. The clean CCSE rule is:if the NAT logic requires service/port translation, use Manual NAT. Reference topic:Configuring the NAT Policy / Working with Manual NAT Rules.
========
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit