ExamGecko
Question list
Search
Search

Related questions











Question 327 - PCNSE discussion

Report
Export

A firewall engineer creates a NAT rule to translate IP address 1.1.1.10 to 192.168.1.10. The engineer also plans to enable DNS rewrite so that the firewall rewrites the IPv4 address in a DNS response based on the original destination IP address and translated destination IP address configured for the rule. The engineer wants the firewall to rewrite a DNS response of 1.1.1.10 to 192.168.1.10.

What should the engineer do to complete the configuration?

A.
Create a U-Turn NAT to translate the destination IP address 192.168.1.10 to 1.1.1.10 with the destination port equal to UDP/53.
Answers
A.
Create a U-Turn NAT to translate the destination IP address 192.168.1.10 to 1.1.1.10 with the destination port equal to UDP/53.
B.
Enable DNS rewrite under the destination address translation in the Translated Packet section of the NAT rule with the direction Forward.
Answers
B.
Enable DNS rewrite under the destination address translation in the Translated Packet section of the NAT rule with the direction Forward.
C.
Enable DNS rewrite under the destination address translation in the Translated Packet section of the NAT rule with the direction Reverse.
Answers
C.
Enable DNS rewrite under the destination address translation in the Translated Packet section of the NAT rule with the direction Reverse.
D.
Create a U-Turn NAT to translate the destination IP address 1.1.1.10 to 192.168.1.10 with the destination port equal to UDP/53.
Answers
D.
Create a U-Turn NAT to translate the destination IP address 1.1.1.10 to 192.168.1.10 with the destination port equal to UDP/53.
Suggested answer: B

Explanation:

If the DNS response matches the Original Destination Address in the rule, translate the DNS response using the same translation the rule uses. For example, if the rule translates IP address 1.1.1.10 to 192.168.1.10, the firewall rewrites a DNS response of 1.1.1.10 to 192.168.1.10. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/nat/source-nat-and-destination-nat/destination-nat-dns-rewrite-use-cases#id0d85db1b-05b9-4956-a467-f71d558263bb

asked 23/09/2024
Vojtech Danek
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first