nerdexam
Check_Point

156-115.77 · Question #21

Tom is troubleshooting NAT issues using fw monitor and Wireshark. He tries to initiate a connection from the external network to a DMZ server using the public IP which the firewall translates to the…

The correct answer is B. The translation might be happening on the server side and the packet is being routed by OS back. See the full explanation below for the reasoning.

Question

Tom is troubleshooting NAT issues using fw monitor and Wireshark. He tries to initiate a connection from the external network to a DMZ server using the public IP which the firewall translates to the actual IP of the server. He analyzes the captured packets using Wireshark and observes that the destination IP is being changed as required by the firewall but does not see the packet leave the external interface. What could be the reason?

Options

  • AThe translation might be happening on the client side and the packet is being routed by the OS
  • BThe translation might be happening on the server side and the packet is being routed by OS back
  • CPacket is dropped by the firewall.
  • DAfter the translation, the packet is dropped by the Anti-Spoofing Protection.

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    73% (29)
  • C
    10% (4)
  • D
    15% (6)

Community Discussion

No community discussion yet for this question.

Full 156-115.77 Practice