Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?
A.
Untrust (any) to Untrust (10.1.1.100), web browsing ג€" Allow
B.
Untrust (any) to Untrust (1.1.1.100), web browsing ג€" Allow
C.
Untrust (any) to DMZ (1.1.1.100), web browsing ג€" Allow
D.
Untrust (any) to DMZ (10.1.1.100), web browsing ג€" Allow
C is the correct answer.
Remember for Security Policy lookup, the firewall uses Pre-NAT IP and Post-NAT Zone.
https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/networking/nat/nat-policy-rules/nat-policy-overview.html
In this scenario, Destination NAT (DNAT) is used to map the public IP address 1.1.1.100 (which is in the Untrust zone) to the private IP address 10.1.1.100 (which is in the DMZ zone). This allows external traffic destined for 1.1.1.100 to be forwarded to the web server at 10.1.1.100.
To allow traffic to flow correctly, the security policy must allow the traffic to enter the DMZ zone using the 1.1.1.100 address, as the NAT process will map this public IP to the internal server.
Should that not be D based on https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-configuration-examples/destination-nat-with-port-translation-example#id053beeb9-fde0-445b-99d0-5dd5a1000b7c ?
I believe the correct answer is 'B'
Since this is DNAT setup, rule for security policy is: PRE-NAT addresses, POST-NAT zone.
PCNSA study guide PAN OS 10.0, p.111
no, C, It then evaluates and applies any security policies that match the packet based on the original (pre-NAT) source and destination addresses, but the post-NAT zones
upvoted 1 times
...
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
trashboat
Highly Voted 3 years, 11 months agoRiiik
Most Recent 3 days, 22 hours agoOswaldo_CCSM
3 months agoYuval711
9 months, 2 weeks agoMarshpillowz
1 year, 2 months agombhuyan
1 year, 10 months agoWoody
2 years, 3 months agoDenskyDen
2 years, 2 months agoTAKUM1y
2 years, 6 months agoconfusion
3 years, 1 month agoKane002
3 years, 4 months agoAngel123
3 years, 10 months agoAngel123
3 years, 10 months agoshetoshandasa
4 years agommed
4 years agowebmanau
4 years agoPrutser2
3 years, 9 months ago