nerdexam
Palo_Alto_Networks

PCNSE · Question #141

Given these tables: an external DNS provider and resolves to 203.1.200.123 in the Untrust-L3 zone. Users in the Trust-L3 zone use the external FQDN to access SVR1. Which NAT rule will process traffic

The correct answer is D. NAT3. This scenario describes a U-Turn NAT (also called hairpin NAT) situation. When internal users in the Trust-L3 zone use an external FQDN that resolves to the public IP 203.1.200.123 (in Untrust-L3), the firewall must apply a NAT rule that matches source zone Trust-L3 and destinati

Submitted by takeshi77· Apr 18, 2026Deploy and Configure

Question

Given these tables:

an external DNS provider and resolves to 203.1.200.123 in the Untrust-L3 zone. Users in the Trust-L3 zone use the external FQDN to access SVR1. Which NAT rule will process traffic sourced from the Trust-L3 zone destined for SVR1?

Exhibits

PCNSE question #141 exhibit 1
PCNSE question #141 exhibit 2

Options

  • ANAT2
  • BNAT4
  • CNAT1
  • DNAT3

How the community answered

(35 responses)
  • A
    9% (3)
  • B
    6% (2)
  • C
    3% (1)
  • D
    83% (29)

Explanation

This scenario describes a U-Turn NAT (also called hairpin NAT) situation. When internal users in the Trust-L3 zone use an external FQDN that resolves to the public IP 203.1.200.123 (in Untrust-L3), the firewall must apply a NAT rule that matches source zone Trust-L3 and destination zone Untrust-L3 (or the public IP). This U-Turn NAT rule performs both destination NAT (translating the public IP to SVR1's private IP) and source NAT (so return traffic is sent back through the firewall, not directly to the client). NAT3 is the rule configured to handle this intra-network hairpin scenario, matching Trust-L3 as both source and destination context routed via the public IP.

Topics

#NAT#U-turn NAT#DNAT#SNAT

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice