Palo_Alto_Networks
NETSEC-ANALYST · Question #181
Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?
The correct answer is D. Untrust (any) to DMZ (1.1.1.100), web browsing -Allow. https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/nat-configuration- examples/destination-nat-exampleone-to-one-mapping
Security Policy and NAT
Question
Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?
Exhibit
Options
- AUntrust (any) to DMZ (10.1.1.100), web browsing -Allow
- BUntrust (any) to Untrust (1.1.1.100), web browsing -Allow
- CUntrust (any) to Untrust (10.1.1.100), web browsing -Allow
- DUntrust (any) to DMZ (1.1.1.100), web browsing -Allow
How the community answered
(49 responses)- A4% (2)
- B14% (7)
- C6% (3)
- D76% (37)
Explanation
https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/networking/nat/nat-configuration- examples/destination-nat-exampleone-to-one-mapping
Topics
#DNAT#Security policy#zone-based firewall#pre-NAT IP matching
Community Discussion
No community discussion yet for this question.
