Which of the following statements about SecureXL NAT Templates is true?
A.
NAT Templates are generated to achieve high session rate for NAT. These templates store the NAT attributes of connections matched by rulebase so that similar new connections can take advantage of this information and do NAT without the expensive rulebase lookup. These are enabled by default and work only if Accept Templates are enabled.
B.
DROP Templates are generated to achieve high session rate for NAT. These templates store the NAT attributes of connections matched by rulebase so that similar new connections can take advantage of this information and do NAT without the expensive rulebase lookup. These are disabled by default and work only if NAT Templates are disabled.
C.
NAT Templates are generated to achieve high session rate for NAT. These templates store the NAT attributes of connections matched by rulebase so that similar new connections can take advantage of this information and do NAT without the expensive rulebase lookup. These are disabled by default and work only if Accept Templates are disabled.
D.
ACCEPT Templates are generated to achieve high session rate for NAT. These templates store the NAT attributes of connections matched by rulebase so that similar new connections can take advantage of this information and do NAT without the expensive rulebase lookup. These are disabled by default and work only if NAT Templates are disabled.
CCSE Page 325
“NAT Templates - Generated to achieve high session rate for NAT. These templates store the NAT attributes of connections matched by rule base so that similar new connections can take advantage of this information and do NAT without the expensive rule base lookup. These are enabled by default and work only if Accept Templates are enabled”
sing SecureXL Templates for NAT traffic is critical to achieve high session rate for NAT.
SecureXL Templates are supported for Static NAT and Hide NAT using the existing SecureXL Templates mechanism.
SecureXL NAT Templates are supported in cluster in High Availability / VRRP, and Load Sharing modes.
SecureXL Templates are supported by VSX Virtual Systems.
SecureXL NAT Templates feature in SecureXL is disabled by default on Check Point Security Gateway R80.10 and below. All template handling in versions R80.20 and above has moved to the Firewall, and is not relevant to SecureXL .
SecureXL implements NAT Templates only once these templates are offloaded by FireWall kernel.
I would say C, as they're disabled by default. However this is seemingly a legacy question, as after R80.20 template handling happens on the firewall, not relevant to SecureXL - likely won't see this question on an R81 exam.
"SecureXL NAT Templates feature in SecureXL is disabled by default on Check Point Security Gateway R80.10 and below. All template handling in versions R80.20 and above has moved to the Firewall, and is not relevant to SecureXL ."
https://support.checkpoint.com/results/sk/sk71200
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
c0be09e
4 months, 1 week agoAraminski
7 months agoreinhardtvdw
11 months, 1 week agopm0565
11 months, 2 weeks agoKeerberus
1 year, 2 months agoObzu
1 year, 3 months agotimmitch1987
1 year, 3 months agoMcBeano
1 year, 3 months ago