PCNSE · Question #141
Given these tables: an external DNS provider and resolves to 203.1.200.123 in the Untrust-L3 zone. Users in the Trust-L3 zone use the external FQDN to access SVR1. Which NAT rule will process traffic
The correct answer is D. NAT3. This scenario describes a U-Turn NAT (also called hairpin NAT) situation. When internal users in the Trust-L3 zone use an external FQDN that resolves to the public IP 203.1.200.123 (in Untrust-L3), the firewall must apply a NAT rule that matches source zone Trust-L3 and destinati
Question
Given these tables:
an external DNS provider and resolves to 203.1.200.123 in the Untrust-L3 zone. Users in the Trust-L3 zone use the external FQDN to access SVR1. Which NAT rule will process traffic sourced from the Trust-L3 zone destined for SVR1?
Exhibits
Options
- ANAT2
- BNAT4
- CNAT1
- DNAT3
How the community answered
(35 responses)- A9% (3)
- B6% (2)
- C3% (1)
- D83% (29)
Explanation
This scenario describes a U-Turn NAT (also called hairpin NAT) situation. When internal users in the Trust-L3 zone use an external FQDN that resolves to the public IP 203.1.200.123 (in Untrust-L3), the firewall must apply a NAT rule that matches source zone Trust-L3 and destination zone Untrust-L3 (or the public IP). This U-Turn NAT rule performs both destination NAT (translating the public IP to SVR1's private IP) and source NAT (so return traffic is sent back through the firewall, not directly to the client). NAT3 is the rule configured to handle this intra-network hairpin scenario, matching Trust-L3 as both source and destination context routed via the public IP.
Topics
Community Discussion
No community discussion yet for this question.

