Palo_Alto_Networks
PCNSE6 · Question #21
A company has a web server behind their Palo Alto Networks firewall that they would like to make accessible to the public. They have decided to configure a destination NAT Policy rule. Given the…
The correct answer is C. Untrust-L3. See the full explanation below for the reasoning.
Question
A company has a web server behind their Palo Alto Networks firewall that they would like to make accessible to the public. They have decided to configure a destination NAT Policy rule. Given the following zone information:
DMZzone: DMZ-L3 Public zone: Untrust-L3 Web server zone: Trust-L3 Public IP address (Untrust-L3): 1.1.1.1 Private IP address (Trust-L3): 192.168.1.50 What should be configured as the destination zone on the Original Packet tab of the NAT Policy rule?
Options
- ADMZ-L3
- BAny
- CUntrust-L3
- DTrust-L3
How the community answered
(22 responses)- A5% (1)
- B18% (4)
- C73% (16)
- D5% (1)
Community Discussion
No community discussion yet for this question.