ExamGecko
Question list
Search
Search

Related questions











Question 269 - PCNSE discussion

Report
Export

A firewall engineer creates a destination static NAT rule to allow traffic from the internet to a webserver hosted behind the edge firewall. The pre-NAT IP address of the server is 153.6 12.10, and the post-NAT IP address is 192.168.10.10.

Refer to the routing and interfaces information below.

What should the NAT rule destination zone be set to?

A.
None
Answers
A.
None
B.
Outside
Answers
B.
Outside
C.
DMZ
Answers
C.
DMZ
D.
Inside
Answers
D.
Inside
Suggested answer: B

Explanation:

The destination zone in the NAT rule is determined after the route lookup of the destination IP address in the original packet (that is, the pre-NAT destination IP address).

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-configurationexamples/destination-nat-exampleone-to-one-mapping

The NAT rule destination zone should be set to the zone where the traffic is destined before NAT. In this case, the traffic from the internet is destined to the pre-NAT IP address of the server, which is 153.6.12.10. This IP address belongs to the Outside zone, as shown in the routing and interfaces information. Therefore, the NAT rule destination zone should be set to Outside. The other options are not correct. None is not a valid option for the NAT rule destination zone. Inside and DMZ are the zones where the traffic is destined after NAT, which is 192.168.10.10. Reference: :

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/networking/nat/source-anddestination-nat/configure-destination-nat

asked 23/09/2024
Antonio Rodriguez
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first