Palo_Alto_Networks
NETSEC-ANALYST · Question #189
Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100
The correct answer is A. Untrust (Any) to DMZ (1.1.1.100), ssh -Allow E. Untrust (Any) to DMZ (1.1.1.100), web-browsing -Allow. You've hit your limit · resets 5am (America/New_York)
Security Policy and NAT
Question
Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and Host B (10.1.1.101) receives SSH traffic. Which two Security policy rules will accomplish this configuration? (Choose two.)
Exhibit
Options
- AUntrust (Any) to DMZ (1.1.1.100), ssh -Allow
- BUntrust (Any) to Untrust (10.1.1.1), web-browsing -Allow
- CUntrust (Any) to Untrust (10.1.1.1), ssh -Allow
- DUntrust (Any) to DMZ (10.1.1.100, 10.1.1.101), ssh, web-browsing -Allow
- EUntrust (Any) to DMZ (1.1.1.100), web-browsing -Allow
How the community answered
(29 responses)- A86% (25)
- B3% (1)
- C7% (2)
- D3% (1)
Explanation
You've hit your limit · resets 5am (America/New_York)
Topics
#DNAT#multi-server NAT#Security policy#zone-based firewall
Community Discussion
No community discussion yet for this question.
