Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium

An organization is deploying a new web application server in a DMZ, which must be accessible from the internet. The security team requires that all inbound connections to this server on port 443 be translated to a specific internal IP address while preserving the source IP of the client for logging purposes. Which NAT type should be configured on the Palo Alto Networks firewall?

  1. ADestination NAT (DNAT)
  2. BStatic IP NAT
  3. CSource NAT (SNAT)
  4. DDynamic IP and Port (DIPP) NAT
Show answer & explanation

Correct answer: A. Destination NAT (DNAT)

Destination NAT (DNAT) is used to change the destination IP address of incoming packets. In this scenario, inbound connections from the internet need their destination IP translated from a public IP to the private IP of the web server, making DNAT the correct choice. It preserves the source IP by default.

Why the other options are wrong

  • B. Static IP NAT typically refers to a one-to-one mapping, which could be DNAT or SNAT, but 'Destination NAT' is the more precise term for this inbound use case.
  • C. Source NAT (SNAT) changes the source IP address of outbound connections, typically from a private IP to a public IP.
  • D. DIPP NAT is a form of Source NAT used for outbound connections, translating multiple internal IPs to a smaller pool of public IPs using port numbers.

Destination NAT (DNAT)

Destination Network Address Translation (DNAT) modifies the destination IP address of an incoming packet, commonly used to expose internal services to external networks.

  • Used for inbound connections.
  • Translates a public IP to a private IP.
  • Often paired with security policies to control access.
  • Preserves the original source IP by default.

Memory trick: NAT Routes Traffic: Source for Out, Destination for In.

More Deploy and Configure questions