Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium

A network administrator is troubleshooting an issue where external users cannot access a web server located in the DMZ (172.16.1.10) from the internet. The internet-facing interface IP is 203.0.113.5. A Security policy rule is already in place to allow the traffic. Which NAT policy configuration is required to allow external users to reach the web server?

  1. ASource NAT (Dynamic IP) from DMZ to Untrust, translating source IP 172.16.1.10 to 203.0.113.5.
  2. BSource NAT (Static IP) from Untrust to DMZ, translating source IP to 203.0.113.5.
  3. CDestination NAT (Static IP) from Untrust to DMZ, translating destination IP 203.0.113.5 to 172.16.1.10.
  4. DDynamic IP and Port (DIPP) NAT from Untrust to DMZ, translating source IP to 203.0.113.5.
Show answer & explanation

Correct answer: C. Destination NAT (Static IP) from Untrust to DMZ, translating destination IP 203.0.113.5 to 172.16.1.10.

To allow external users to access an internal server, Destination NAT (DNAT) is required. The public IP (203.0.113.5) that external users connect to must be translated to the private IP of the web server (172.16.1.10).

Why the other options are wrong

  • A. This describes a Source NAT rule for outbound traffic from the DMZ, which is not the primary issue preventing external access.
  • B. Source NAT is for internal users accessing external resources, not external users accessing internal resources.
  • D. Dynamic IP and Port (DIPP) NAT is a form of Source NAT, used for outbound connections, not inbound.

Destination NAT (DNAT)

A type of Network Address Translation (NAT) that translates the destination IP address of incoming traffic. It is used to allow external users to access internal servers that have private IP addresses by mapping a public IP to a private one.

  • Translates the destination IP of a packet.
  • Used for inbound connections from external networks to internal servers.
  • Requires a public IP address (or interface IP) to be mapped to a private server IP.
  • Often combined with a Security Policy to permit the translated traffic.

Memory trick: Destination NAT directs external calls to internal servers.

More Deploy and Configure questions