PrepAway - Latest Free Exam Questions & Answers

which situation is NAT proxy NDP required?

In which situation is NAT proxy NDP required?

PrepAway - Latest Free Exam Questions & Answers

A.
when translated addresses belong to the same subnet as the ingress interface

B.
when filter-based forwarding and static NAT are used on the same interface

C.
when working with static NAT scenarios

D.
when the security device operates in transparent mode

Explanation:

WhenIP addressesarein the same subnet of the ingressinterface,NAT proxy ARPconfigured

Reference :http://www.juniper.net/techpubs/en_US/junos12.1×44/information-products/pathwaypages/security/security-nat.pdf
Reference :http://www.juniper.net/techpubs/en_US/junos-space12.2/topics/concept/junos-spacesecurity-designer-whiteboard-nat-overview.html

12 Comments on “which situation is NAT proxy NDP required?

  1. Silver coin says:

    Proxy-ARP and Proxy-NDP are required for IPv4 and IPv6, respectively, when you are
    performing NAT and using a public range that is local to the subnet of the egress interface rather than a routed subnet.
    There is no limit on the type of NAT being used with proxy ARP/NDP except the interface based source NAT and when the pool is different from the interface subnet.
    Therefore the answer A makes more sense from the answers offered.




    0



    0
  2. Ratheesh Ravindran says:

    Answer is A.

    Proxy NAT NDP required in IPV6 address source nat configuration where in which we are using source nat with public pool ip other than interface IP of the untrust interface.




    0



    0
  3. JuniperCorrect says:

    ingress – entering

    egress – exiting

    The ingress port is the incoming port. The egress port is the exiting port.

    Proxy NDP ia used mostly in NAT64 & NAT46 scenarios . both scenarios is needed to configure proxy arp and proxy ndp , where the proxy arp is the address on the ingress interface and the proxy ndp is the adress on the egress interface , and both addresses needed to talk to each other .

    both scenarios are using one to one translating .
    So answer A is not that correct . and C are most correct answer .

    please correct me if im wrong .

    Look at AJsec volume 1 of 2 , chapter 5 page 38-39




    0



    0
  4. Alex says:

    -A- all life.

    Proxy NDP does (in IPv6) the same function of proxy-ARP (in IPv4).

    This link well explain WHEN to use Proxy ARP:
    http://kb.juniper.net/InfoCenter/index?page=content&id=KB21785&actp=search

    *When addresses defined in the static NAT and source NAT pool are in the same subnet as that of the ingress interface (Source NAT and Static NAT scenario)
    *When addresses in the original destination address entry in the destination NAT rules are in the same subnet as that of the ingress interface (Destination NAT scenario)




    0



    0
  5. Mahmoud says:

    Answer A is more correct and specific (case Source NAT with Pool) , other option are generic , the general role for proxy-arp and proxy-arp-ND when traffic is entering interface (ingress)destination for IP on the same subnet of the this interface .

    we have two case

    case 1 destination NAT , Static Nat
    request coming for the pre-NAT Address (normal Direction)

    Case 2 source NAT with Pool
    in this Case the request come to the post-nat Address (reverse Static NAT )

    hope this will remove confusion

    Thanks




    0



    0
  6. ahmed says:

    •For source NAT, the proxy NDP is available for NAT pool addresses.
    *For destination NAT and static NAT, the proxy NDP is available for destination NAT addresses.




    0



    0

Leave a Reply