Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium

A network security administrator needs to configure a NAT policy to allow internal users to access an external web server using a specific public IP address that is different from the firewall's egress interface IP. Which type of NAT configuration is required?

  1. AStatic IP NAT
  2. BDestination NAT (DNAT)
  3. CSource NAT (SNAT)
  4. DDynamic IP and Port (DIPP) NAT
Show answer & explanation

Correct answer: A. Static IP NAT

When internal users need to appear to originate from a specific, consistent public IP address (not necessarily the egress interface IP or a pool) when accessing external resources, Static IP NAT for the source is used. This maps internal source IPs to a consistent external public IP.

Why the other options are wrong

  • B. Destination NAT is used for inbound traffic to internal servers, changing the destination IP.
  • C. Source NAT (SNAT) is the general term for changing the source IP; Static IP NAT is a specific type of SNAT.
  • D. Dynamic IP and Port (DIPP) NAT uses a pool of IP addresses or the egress interface IP, and port numbers, which doesn't guarantee a single specific public IP for all outbound connections.

Static IP NAT (Source)

Static IP NAT (Source) on a Palo Alto Networks firewall maps one or more internal source IP addresses to a consistent, specific public IP address for outbound connections, ensuring a predictable external identity.

  • Maps internal IP to a single public IP.
  • Used for outbound connections.
  • Ensures consistent external IP for internal hosts.

Memory trick: Static IP NAT is the 'Consistent Caller ID' for your internal network.

More Deploy and Configure questions