nerdexam
Cisco

300-710 · Question #422

An engineer is configuring Cisco Secure Firewall Threat Defense managed by a Secure Firewall Management Center appliance. The company wants remote access VPN users to be reachable from the inside netw

The correct answer is A. manual NAT exemption rule at the top of the NAT policy. When remote access VPN users connect, their traffic enters the FTD through the VPN tunnel and exits toward the inside network. Without a NAT exemption, the FTD may attempt to apply NAT translations to this traffic, breaking connectivity between inside hosts and VPN clients. A man

Configuration

Question

An engineer is configuring Cisco Secure Firewall Threat Defense managed by a Secure Firewall Management Center appliance. The company wants remote access VPN users to be reachable from the inside network. What must the engineer configure to meet the requirements?

Options

  • Amanual NAT exemption rule at the top of the NAT policy
  • Bmanual NAT exemption rule at the bottom of the NAT policy
  • Cauto NAT exemption rule at the top of the NAT policy
  • Dauto NAT exemption rule at the bottom of the NAT policy

How the community answered

(51 responses)
  • A
    71% (36)
  • B
    16% (8)
  • C
    8% (4)
  • D
    6% (3)

Explanation

When remote access VPN users connect, their traffic enters the FTD through the VPN tunnel and exits toward the inside network. Without a NAT exemption, the FTD may attempt to apply NAT translations to this traffic, breaking connectivity between inside hosts and VPN clients. A manual NAT exemption rule (identity NAT / no-translate rule) must be placed at the TOP of the NAT policy because FMC processes NAT rules in order-manual NAT rules are evaluated before auto NAT rules. Placing it at the top ensures the exemption is matched first, before any other NAT rule could incorrectly translate the traffic. A rule at the bottom (B) risks being overshadowed by other rules. Auto NAT (C, D) cannot be reliably placed at the top of the policy in the same way manual NAT can.

Topics

#FTD NAT#Remote Access VPN#NAT Exemption#NAT Policy Order

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice