nerdexam
Palo_Alto_Networks

PSE-PLATFORM · Question #103

The web server is configured to listen for HTTP traffic on port 8080. The clients access the web server using the IP address 1.1.1.100 on TCP Port 80. The destination NAT rule is configured to…

The correct answer is C. A NAT rule with a source of any from untrust-I3 zone to a destination of 1.1.1.100 in untrust-I3 zone using service-http service. D. A security policy with a source of any from untrust-I3 zone to a destination of 1.1.100 in dmz-I3 zone using web-browsing application. Explanation/Reference:

Security Policy and NAT Configuration

Question

The web server is configured to listen for HTTP traffic on port 8080. The clients access the web server using the IP address 1.1.1.100 on TCP Port 80. The destination NAT rule is configured to translate both IP address and report to 10.1.1.100 on TCP Port 8080. Which NAT and security rules must be configured on the firewall? (Choose two)

Exhibit

PSE-PLATFORM question #103 exhibit

Options

  • AA security policy with a source of any from untrust-I3 Zone to a destination of 10.1.1.100 in dmz-I3 zone using web-browsing application
  • BA NAT rule with a source of any from untrust-I3 zone to a destination of 10.1.1.100 in dmz-zone using service-http service.
  • CA NAT rule with a source of any from untrust-I3 zone to a destination of 1.1.1.100 in untrust-I3 zone using service-http service.
  • DA security policy with a source of any from untrust-I3 zone to a destination of 1.1.100 in dmz-I3 zone using web-browsing application.

How the community answered

(25 responses)
  • A
    20% (5)
  • B
    12% (3)
  • C
    68% (17)

Explanation

Explanation/Reference:

Topics

#Destination NAT#Port translation#Pre-NAT zones#Security policy zones

Community Discussion

No community discussion yet for this question.

Full PSE-PLATFORM Practice