Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium
A network security administrator needs to configure a NAT policy to allow internal users to access an external web server using a specific public IP address that is different from the firewall's egress interface IP. Which type of NAT configuration is required?
- AStatic IP NAT
- BDestination NAT (DNAT)
- CSource NAT (SNAT)
- DDynamic IP and Port (DIPP) NAT
Show answer & explanationAnswer & explanation
Correct answer: A. Static IP NAT
When internal users need to appear to originate from a specific, consistent public IP address (not necessarily the egress interface IP or a pool) when accessing external resources, Static IP NAT for the source is used. This maps internal source IPs to a consistent external public IP.
Why the other options are wrong
- B. Destination NAT is used for inbound traffic to internal servers, changing the destination IP.
- C. Source NAT (SNAT) is the general term for changing the source IP; Static IP NAT is a specific type of SNAT.
- D. Dynamic IP and Port (DIPP) NAT uses a pool of IP addresses or the egress interface IP, and port numbers, which doesn't guarantee a single specific public IP for all outbound connections.
Static IP NAT (Source)
Static IP NAT (Source) on a Palo Alto Networks firewall maps one or more internal source IP addresses to a consistent, specific public IP address for outbound connections, ensuring a predictable external identity.
- Maps internal IP to a single public IP.
- Used for outbound connections.
- Ensures consistent external IP for internal hosts.
Memory trick: Static IP NAT is the 'Consistent Caller ID' for your internal network.