PCNSE · Question #676
If an administrator wants to apply QoS to traffic based on source, what must be specified in a QoS policy rule?
The correct answer is C. Pre-NAT source address. Palo Alto Networks QoS policy rules, like Security policy rules, are evaluated using pre-NAT source addresses. This is because the packet processing order places NAT after policy lookup - the firewall matches policies against the original (pre-NAT) addresses before translating…
Question
If an administrator wants to apply QoS to traffic based on source, what must be specified in a QoS policy rule?
Options
- APost-NAT destination address
- BPre-NAT destination address
- CPre-NAT source address
- DPost-NAT source address
How the community answered
(30 responses)- B7% (2)
- C90% (27)
- D3% (1)
Explanation
Palo Alto Networks QoS policy rules, like Security policy rules, are evaluated using pre-NAT source addresses. This is because the packet processing order places NAT after policy lookup - the firewall matches policies against the original (pre-NAT) addresses before translating them. Specifying a pre-NAT source address in the QoS rule ensures the policy correctly identifies the originating host. Using post-NAT addresses would be incorrect because the translated address is not yet known at policy evaluation time. Destination address fields in QoS policy are also pre-NAT, so post-NAT destination is similarly not applicable.
Topics
Community Discussion
No community discussion yet for this question.