nerdexam
Palo_Alto_Networks

PCNSE7 · Question #141

Given these tables: an external DNS provider and resolves to 203.1.200.123 in the Untrust-L3 zone. Users in the Trust-L3 zone use the external FQDN to access SVR1. Which NAT rule will process…

The correct answer is C. NAT1. NAT 2 doesn't make sense if the users on the trust zone are using the external fqdn to reach the SRV1 that means they are going out to internet and they must hit the untrust interface on the fw, if this is destination nat, the correct answer must be NAT1.

Troubleshoot and Optimize

Question

Given these tables:

an external DNS provider and resolves to 203.1.200.123 in the Untrust-L3 zone. Users in the Trust-L3 zone use the external FQDN to access SVR1. Which NAT rule will process traffic sourced from the Trust-L3 zone destined for SVR1?

Exhibits

PCNSE7 question #141 exhibit 1
PCNSE7 question #141 exhibit 2

Options

  • ANAT2
  • BNAT4
  • CNAT1
  • DNAT3

How the community answered

(17 responses)
  • A
    12% (2)
  • B
    6% (1)
  • C
    76% (13)
  • D
    6% (1)

Explanation

NAT 2 doesn't make sense if the users on the trust zone are using the external fqdn to reach the SRV1 that means they are going out to internet and they must hit the untrust interface on the fw, if this is destination nat, the correct answer must be NAT1.

Topics

#NAT policy#U-turn NAT#destination NAT#traffic flow analysis

Community Discussion

No community discussion yet for this question.

Full PCNSE7 Practice