PCNSE · Question #678
A firewall engineer creates a destination static NAT rule to allow traffic from the internet to a webserver hosted behind the edge firewall. The pre-NAT IP address of the server is 153.6.12.10, and…
The correct answer is B. Inside. In PAN-OS, the destination zone in a NAT rule is matched against the pre-NAT destination zone, which is determined by a routing table lookup on the pre-NAT destination IP (153.6.12.10) - not by the ingress interface. Based on the routing and interface information referenced in…
Question
A firewall engineer creates a destination static NAT rule to allow traffic from the internet to a webserver hosted behind the edge firewall. The pre-NAT IP address of the server is 153.6.12.10, and the post-NAT IP address is 192.168.10.10. Refer to the routing and interfaces information below. What should the NAT rule destination zone be set to?
Exhibits
Options
- ANone
- BInside
- CDMZ
- DOutside
How the community answered
(17 responses)- B94% (16)
- D6% (1)
Explanation
In PAN-OS, the destination zone in a NAT rule is matched against the pre-NAT destination zone, which is determined by a routing table lookup on the pre-NAT destination IP (153.6.12.10) - not by the ingress interface. Based on the routing and interface information referenced in the question, the route for 153.6.12.10 resolves to the Inside zone (the organization owns this public IP block and it is reachable via the Inside interface). Therefore, the NAT rule destination zone must be set to 'Inside' (B) to match the pre-NAT routing result. Choosing 'Outside' would be incorrect because that reflects the ingress zone, not the zone resolved by the routing lookup for the pre-NAT destination.
Topics
Community Discussion
No community discussion yet for this question.

