nerdexam
Palo_Alto_Networks

PCNSE · Question #247

Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?

The correct answer is C. Untrust (any) to DMZ (1.1.1.100), web browsing -Allow. In PAN-OS, Security policy evaluation for DNAT uses the pre-NAT destination IP address but the post-NAT destination zone. The public IP (1.1.1.100) is the pre-NAT address (what the client sends to), and DMZ is the post-NAT zone (where the server actually lives). The rule must mat

Submitted by lars.no· Apr 18, 2026Deploy and Configure

Question

Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?

Exhibit

PCNSE question #247 exhibit

Options

  • AUntrust (any) to Untrust (10.1.1.100), web browsing -Allow
  • BUntrust (any) to Untrust (1.1.1.100), web browsing -Allow
  • CUntrust (any) to DMZ (1.1.1.100), web browsing -Allow
  • DUntrust (any) to DMZ (10.1.1.100), web browsing -Allow

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    81% (17)
  • D
    10% (2)

Explanation

In PAN-OS, Security policy evaluation for DNAT uses the pre-NAT destination IP address but the post-NAT destination zone. The public IP (1.1.1.100) is the pre-NAT address (what the client sends to), and DMZ is the post-NAT zone (where the server actually lives). The rule must match source zone Untrust, destination zone DMZ (post-NAT), and destination address 1.1.1.100 (pre-NAT public IP). Option D is wrong because 10.1.1.100 is the private/post-NAT IP, which is not used in the Security policy.

Topics

#DNAT#Security Policy Rules#Firewall Zones#Policy Evaluation

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice