exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 501 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 501
Topic #: 1
[All PCNSE Questions]

A firewall engineer creates a destination static NAT rule to allow traffic from the internet to a webserver hosted behind the edge firewall. The pre-NAT IP address of the server is 153.6.12.10, and the post-NAT IP address is 192.168.10.10. Refer to the routing and interfaces information below.





What should the NAT rule destination zone be set to?

  • A. None
  • B. Inside
  • C. DMZ
  • D. Outside
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jhoncena
Highly Voted 1 year, 8 months ago
Answer should be D .. Outside to outside based on below : The destination zone in the NAT rule is determined after the route lookup of the destination IP address in the original packet (that is, the pre-NAT destination IP address). https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping
upvoted 13 times
[Removed]
1 year, 6 months ago
Good thinking you are correct, but check again the Routing table...
upvoted 3 times
...
jhoncena
1 year, 8 months ago
I know both routing entries refer to Inside but the question is asking about the configuration part not the logical flow .. we need to configure outside > to > outside
upvoted 3 times
jhoncena
1 year, 8 months ago
No Inside should be correct : )
upvoted 4 times
...
...
...
Knowledge33
Highly Voted 1 year, 7 months ago
Selected Answer: D
The answer is D, not B guys. We don't care about the routing table. When a paccket arrive on the outside Interface, The PAN checks first if there is a DNAT configured for this trafic, and If the trafic is allowed. Then It can proceed with the forwarding lookup (Routing table). That's why we need Outside>Outside NAT. B is totally wrong. There is no NAT on the Inside zone. FOrget the Routing table. It doesn't matter.
upvoted 10 times
Knowledge33
1 year, 6 months ago
My bad. The response is B
upvoted 8 times
Eluis007
8 months, 1 week ago
A NAT rule is configured based on the zone associated with a pre-NAT IP address. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-policy-rules/nat-policy-overview
upvoted 4 times
scanossa
5 months ago
Answer is D, a NAT rule is configured based on the zone associated with a pre-NAT IP address
upvoted 1 times
...
...
...
laroux
1 year, 7 months ago
> The destination zone in the NAT rule is determined after the route lookup of the destination IP address in the original packet (that is, the pre-NAT destination IP address). https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping
upvoted 1 times
...
...
kewokil120
Most Recent 1 day ago
Selected Answer: D
Answer is D. Refer to https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping and the first image.
upvoted 1 times
...
Pretorian
2 weeks, 4 days ago
Selected Answer: D
D is correct - Original packet for DNAT is untrust to untrust for zone.
upvoted 1 times
...
corpguy
2 weeks, 6 days ago
Selected Answer: D
Should be the Untrust or outside zone to/from regardless of the routing table.
upvoted 1 times
...
362c603
2 months ago
Selected Answer: D
took and passed exam today. I answered Outside. DNAT Source and DST Zone should be PreNAT zone. I got few new questions that aren't here. If you at least study the concept and use this website as an extra study material, you should be good.
upvoted 2 times
...
Cosmonauta
2 months, 3 weeks ago
The correct answer should be B, first the packet could go through the firewall without nat, then the destination can be changed while it goes from false to internal, after nat the firewall knows the route to follow.
upvoted 1 times
...
this was in my exam 09/08/2024
upvoted 2 times
...
Bau24
4 months, 3 weeks ago
Selected Answer: B
The pre-nat ip address is not on firewall itself and just routed to the inside network, so the Destination zone will be INSIDE
upvoted 2 times
...
Bau24
4 months, 3 weeks ago
Selected Answer: B
B -Inside
upvoted 1 times
...
scanossa
4 months, 3 weeks ago
This question was on my exam on July 23rd, 2024
upvoted 1 times
...
ATRRHMN
5 months ago
Selected Answer: B
Pre-NAT IP is 153.6.12.10 Post-NAT zone is the one found after routing lookup which is "inside" --> next-hop for 192.168.10.0/24 is set to 192.168.1.2 (Eth1/2) which is in the inside zone.
upvoted 1 times
...
scanossa
5 months, 2 weeks ago
Selected Answer: B
Pre-destination IP is also in the Inside zone, check the routing table, it is a tricky question
upvoted 1 times
...
0d2fdfa
6 months, 2 weeks ago
Selected Answer: D
outside to outside. always remember No Zone change for NAT. For Security Policy Pre NAT IP and POST NAT Zone.
upvoted 3 times
...
Icke1973
8 months ago
Selected Answer: B
net 153.6.12.0/27 will be routed to inside and is not an outside ip.
upvoted 6 times
...
hcir
9 months ago
I just tested it in the lab, and the answer is B. Inside. NAT uses the pre-NAT zone. The Zone is determined by the route lookup which for the destination IP is "inside".
upvoted 5 times
...
cloudconnect
9 months, 2 weeks ago
Selected Answer: D
The webserver having this 153.6.12.10 address that appears to be reachable through eth1/2 on the inside zone is a U-NAT situation - where internal users need to access a server using the server's external public IP instead of its private IP address. But, it doesn't mean that the internet users are accessing the network through eth1/2 on the firewall, as shown in route table.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago