Exam 156-561 Topic 2 Question 58 Discussion
Actual exam question for CheckPoint's 156-561 exam
Question #: 58
Topic #: 2
Question #: 58
Topic #: 2
What is an alternative method to double NAT in Azure?
Suggested Answer: B Vote an answer
by blu3b34rd at Nov 19, 2025, 12:17 PM
0
0
0
10
Comments
blu3b34rd
2025-11-19 12:17:54The official Check Point and Microsoft recommended alternative to double NAT is to use User-Defined Routes (UDR):
Route 0.0.0.0/0 (Internet-bound traffic) from spoke/workload subnets → Next Hop = Check Point gateway (or Internal Load Balancer in front of the CloudGuard cluster/scale-set).
The Check Point gateway performs Hide NAT (source NAT) itself using its own public IPs/EIPs on the external interface.
No Azure NAT Gateway or instance-level public IPs are used on the workloads → only one NAT translation occurs (on the Check Point gateway).
This gives full visibility, proper return path symmetry, and stateful firewalling.
Why the other options are wrong
OptionStatementWhy incorrectASystem RoutesSystem routes send traffic to the Internet directly (or via NAT Gateway if attached) → causes double NAT or bypasses the gateway entirelyBPeeringVNet peering only connects VNets; it does not replace NAT or routing for Internet egressCScalingScaling (horizontal/vertical) has nothing to do with avoiding NAT
Official references (still valid 2025):
Check Point Azure deployment guides (Transit VNet design)
Microsoft + Check Point joint reference architecture
SK109360, sk173925, and Azure CloudGuard templates all explicitly state: use UDR with 0.0.0.0/0 pointing to CloudGuard as the method to avoid double NAT.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).