nerdexam
Palo_Alto_Networks

PSE-PLATFORM · Question #95

A company hosts a publically accessible web server behind a Palo Alto Networks next generation firewall with the following configuration information. - Users outside the company are in the "Untrust-L3

The correct answer is A. Untrust-L3 for both Source and Destination zone D. Destination IP of 23.54.6.10. Explanation/Reference:

Security Policy and NAT Configuration

Question

A company hosts a publically accessible web server behind a Palo Alto Networks next generation firewall with the following configuration information.

  • Users outside the company are in the "Untrust-L3" zone
  • The web server physically resides in the "Trust-L3" zone.
  • Web server public IP address: 23.54.6.10
  • Web server private IP address: 192.168.1.10

Which two items must be NAT policy contain to allow users in the untrust-L3 zone to access the web server? (Choose two)

Options

  • AUntrust-L3 for both Source and Destination zone
  • BDestination IP of 192.168.1.10
  • CUntrust-L3 for Source Zone and Trust-L3 for Destination Zone
  • DDestination IP of 23.54.6.10

How the community answered

(18 responses)
  • A
    83% (15)
  • B
    6% (1)
  • C
    11% (2)

Explanation

Explanation/Reference:

Topics

#Destination NAT#Security zones#NAT policy#Public IP translation

Community Discussion

No community discussion yet for this question.

Full PSE-PLATFORM Practice