nerdexam
Palo_Alto_Networks

PSE-PLATFORM · Question #88

What must be used in Security Policy Rule that contain addresses where NAT policy applies?

The correct answer is C. Pre-NAT addresse and Post-Nat zones. Explanation/Reference: NAT Policy Rule Functionality Upon ingress, the firewall inspects the packet and does a route lookup to determine the egress interface and zone. Then the firewall determines if the packet matches one of the NAT rules that have been defined, based on…

Security Policy and NAT Configuration

Question

What must be used in Security Policy Rule that contain addresses where NAT policy applies?

Options

  • APre-NAT addresse and Pre-NAT zones
  • BPost-NAT addresse and Post-Nat zones
  • CPre-NAT addresse and Post-Nat zones
  • DPost-Nat addresses and Pre-NAT zones

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    78% (28)
  • D
    14% (5)

Explanation

Explanation/Reference: NAT Policy Rule Functionality Upon ingress, the firewall inspects the packet and does a route lookup to determine the egress interface and zone. Then the firewall determines if the packet matches one of the NAT rules that have been defined, based on source and/or destination zone. It then evaluates and applies any security policies that match the packet based on the original (pre-NAT) source and destination addresses, but the post-NAT zones.

Topics

#NAT policy#Security policy#Pre-NAT addressing#Zone mapping

Community Discussion

No community discussion yet for this question.

Full PSE-PLATFORM Practice