300-710 · Question #422
An engineer is configuring Cisco Secure Firewall Threat Defense managed by a Secure Firewall Management Center appliance. The company wants remote access VPN users to be reachable from the inside netw
The correct answer is A. manual NAT exemption rule at the top of the NAT policy. When remote access VPN users connect, their traffic enters the FTD through the VPN tunnel and exits toward the inside network. Without a NAT exemption, the FTD may attempt to apply NAT translations to this traffic, breaking connectivity between inside hosts and VPN clients. A man
Question
An engineer is configuring Cisco Secure Firewall Threat Defense managed by a Secure Firewall Management Center appliance. The company wants remote access VPN users to be reachable from the inside network. What must the engineer configure to meet the requirements?
Options
- Amanual NAT exemption rule at the top of the NAT policy
- Bmanual NAT exemption rule at the bottom of the NAT policy
- Cauto NAT exemption rule at the top of the NAT policy
- Dauto NAT exemption rule at the bottom of the NAT policy
How the community answered
(51 responses)- A71% (36)
- B16% (8)
- C8% (4)
- D6% (3)
Explanation
When remote access VPN users connect, their traffic enters the FTD through the VPN tunnel and exits toward the inside network. Without a NAT exemption, the FTD may attempt to apply NAT translations to this traffic, breaking connectivity between inside hosts and VPN clients. A manual NAT exemption rule (identity NAT / no-translate rule) must be placed at the TOP of the NAT policy because FMC processes NAT rules in order-manual NAT rules are evaluated before auto NAT rules. Placing it at the top ensures the exemption is matched first, before any other NAT rule could incorrectly translate the traffic. A rule at the bottom (B) risks being overshadowed by other rules. Auto NAT (C, D) cannot be reliably placed at the top of the policy in the same way manual NAT can.
Topics
Community Discussion
No community discussion yet for this question.