Palo Alto Networks Certified Network Security Engineer (PCNSE)Plan and DesignEasy
A network architect is designing a NAT policy for a new segment of IoT devices. These devices need to access external cloud services using a single public IP address, and their internal IP addresses must be hidden from the internet. The design requires that outbound connections initiate from the IoT devices to the cloud services. Which NAT type is most appropriate for this scenario?
- AStatic IP NAT
- BDynamic IP Source NAT
- CDestination NAT (DNAT)
- DDynamic IP and Port (DIPP) Source NAT
Show answer & explanationAnswer & explanation
Correct answer: D. Dynamic IP and Port (DIPP) Source NAT
Dynamic IP and Port (DIPP) Source NAT (also known as PAT or NAPT) is the most appropriate NAT type. It allows multiple internal IP addresses (IoT devices) to share a single public IP address for outbound connections, translating both the source IP and port while hiding the internal network topology.
Why the other options are wrong
- A. Static IP NAT maps one internal IP to one public IP, which is inefficient for many IoT devices sharing a single public IP.
- B. Dynamic IP Source NAT maps multiple internal IPs to a pool of public IPs, but it doesn't necessarily use a single public IP and doesn't translate ports, which is less efficient for sharing a single IP.
- C. Destination NAT (DNAT) is used for inbound connections to internal servers, not for outbound connections from internal devices.
Dynamic IP and Port (DIPP) Source NAT
DIPP Source NAT (PAT) translates multiple internal source IP addresses and their ports to a single public IP address and different port numbers for outbound connections.
- Allows many-to-one IP address translation.
- Translates both source IP and source port.
- Hides internal network from the internet.
- Commonly used for outbound internet access.
Memory trick: Source NAT says: 'WHO' is going 'OUT' and on 'WHAT' port?