NETSEC-ANALYST · Question #319
An administrator is trying to understand which NAT policy is being matched. In what order does the firewall evaluate NAT policies?
The correct answer is B. From top to bottom. You configure a NAT rule to match a packet's source zone and destination zone, at a minimum. In addition to zones, you can configure matching criteria based on the packet's destination interface, source and destination address, and service. You can configure multiple NAT rules…
Question
An administrator is trying to understand which NAT policy is being matched. In what order does the firewall evaluate NAT policies?
Options
- ADynamic IP and Port first, then Static, and finally Dynamic IP
- BFrom top to bottom
- CStatic NAT rules first, then lop down
- DStatic NAT rules first, then Dynamic
How the community answered
(34 responses)- A12% (4)
- B76% (26)
- C3% (1)
- D9% (3)
Explanation
You configure a NAT rule to match a packet's source zone and destination zone, at a minimum. In addition to zones, you can configure matching criteria based on the packet's destination interface, source and destination address, and service. You can configure multiple NAT rules. The firewall evaluates the rules in order from the top down. Once a packet matches the criteria of a single NAT rule, the packet is not subjected to additional NAT rules. Therefore, your list of NAT rules should be in order from most specific to least specific so that packets are subjected to the most specific rule you created for them. https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-networking-admin/nat/nat-policy-rules/nat-
Topics
Community Discussion
No community discussion yet for this question.