Palo_Alto_Networks
PCNSC · Question #46
Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?
The correct answer is C. Untrust (any) to DMZ (1.1.1.100), web browsing - Allow. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-configuration- examples/ destination-nat-exampleone-to-one-mapping.html#ide8f6a4b3-f875-4855-acb5-
Security Policy and Application Identification
Question
Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?
Exhibit
Options
- AUntrust (any) to Untrust (10.1.1.100), web browsing - Allow
- BUntrust (any) to Untrust (1.1.1.100), web browsing - Allow
- CUntrust (any) to DMZ (1.1.1.100), web browsing - Allow
- DUntrust (any) to DMZ (10.1.1.100), web browsing - Allow
How the community answered
(55 responses)- A4% (2)
- B4% (2)
- C80% (44)
- D13% (7)
Explanation
https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-configuration- examples/ destination-nat-exampleone-to-one-mapping.html#ide8f6a4b3-f875-4855-acb5-
Topics
#DNAT#NAT policy#security policy zones#DMZ
Community Discussion
No community discussion yet for this question.
