Regarding Hide NAT(PAT)

Unanswered Question
Jan 2nd, 2009
User Badges:

Dear Team,

Whether doing Hide NAT(Hide behind IP or Hide behind Gateway) will automatically add two rules in the rulebase.

For example If someone from internal network want to access external public IP

Internal Network

External IP:- IP)


Now when the internal network accesses the public IP it will get Hide NATed to the public IP

Will that mean the one more rulebase will get created automatically(because of Hide NAT) which will mean that the external IP ( can access and then this IP will get NATed to

Am I correct?

If yes then will that mean that at a time either internal network can access external IP OR external IP can access internal network.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
cisco24x7 Fri, 01/02/2009 - 06:17
User Badges:
  • Silver, 250 points or more

With Checkpoint:

NAT is independent with security rules. You

need to define both "hide" NAT and add security

rules for inside to get to outside. Most

security folks prefer it this way. Always

deny unless explicitly allow.

With Cisco:

by default, inside is allowed to traverse to

outside unless explicitly deny. This is very


Either way, with Cisco, once you define

PAT/NAT, inside hosts can communicate

with outside hosts, by default, unless

explicitly denies.

Easy right?


This Discussion