nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #319

An administrator is trying to understand which NAT policy is being matched. In what order does the firewall evaluate NAT policies?

The correct answer is B. From top to bottom. You configure a NAT rule to match a packet's source zone and destination zone, at a minimum. In addition to zones, you can configure matching criteria based on the packet's destination interface, source and destination address, and service. You can configure multiple NAT rules…

NAT Configuration

Question

An administrator is trying to understand which NAT policy is being matched. In what order does the firewall evaluate NAT policies?

Options

  • ADynamic IP and Port first, then Static, and finally Dynamic IP
  • BFrom top to bottom
  • CStatic NAT rules first, then lop down
  • DStatic NAT rules first, then Dynamic

How the community answered

(34 responses)
  • A
    12% (4)
  • B
    76% (26)
  • C
    3% (1)
  • D
    9% (3)

Explanation

You configure a NAT rule to match a packet's source zone and destination zone, at a minimum. In addition to zones, you can configure matching criteria based on the packet's destination interface, source and destination address, and service. You can configure multiple NAT rules. The firewall evaluates the rules in order from the top down. Once a packet matches the criteria of a single NAT rule, the packet is not subjected to additional NAT rules. Therefore, your list of NAT rules should be in order from most specific to least specific so that packets are subjected to the most specific rule you created for them. https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-networking-admin/nat/nat-policy-rules/nat-

Topics

#NAT policy#policy evaluation order#top-to-bottom matching#rule matching

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice