PCNSE · Question #247
Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?
The correct answer is C. Untrust (any) to DMZ (1.1.1.100), web browsing -Allow. In PAN-OS, Security policy evaluation for DNAT uses the pre-NAT destination IP address but the post-NAT destination zone. The public IP (1.1.1.100) is the pre-NAT address (what the client sends to), and DMZ is the post-NAT zone (where the server actually lives). The rule must mat
Question
Refer to the exhibit. A web server in the DMZ is being mapped to a public address through DNAT. Which Security policy rule will allow traffic to flow to the web server?
Exhibit
Options
- AUntrust (any) to Untrust (10.1.1.100), web browsing -Allow
- BUntrust (any) to Untrust (1.1.1.100), web browsing -Allow
- CUntrust (any) to DMZ (1.1.1.100), web browsing -Allow
- DUntrust (any) to DMZ (10.1.1.100), web browsing -Allow
How the community answered
(21 responses)- A5% (1)
- B5% (1)
- C81% (17)
- D10% (2)
Explanation
In PAN-OS, Security policy evaluation for DNAT uses the pre-NAT destination IP address but the post-NAT destination zone. The public IP (1.1.1.100) is the pre-NAT address (what the client sends to), and DMZ is the post-NAT zone (where the server actually lives). The rule must match source zone Untrust, destination zone DMZ (post-NAT), and destination address 1.1.1.100 (pre-NAT public IP). Option D is wrong because 10.1.1.100 is the private/post-NAT IP, which is not used in the Security policy.
Topics
Community Discussion
No community discussion yet for this question.
