A network administrator is troubleshooting an issue where a newly deployed internal server, accessible via its private IP 10.0.0.5, needs to be reached from external networks using a public IP 203.0.113.10. The administrator has configured a Destination NAT (D-NAT) rule to translate 203.0.113.10 to 10.0.0.5. However, external users are still unable to connect. What critical additional configuration is most likely missing for external users to successfully reach the server?
- AA Decryption Policy rule to decrypt traffic destined for 203.0.113.10.
- BAn App-ID override for the server's application.
- CA Source NAT (S-NAT) rule to translate the server's source IP.
- DA Security Policy rule allowing traffic from the external zone to the internal zone for the server's service.
Show answer & explanationAnswer & explanation
Correct answer: D. A Security Policy rule allowing traffic from the external zone to the internal zone for the server's service.
While D-NAT handles the IP translation, it does not implicitly allow traffic through the firewall. A security policy rule is always required to explicitly permit traffic from the external zone (where users originate) to the internal zone (where the server resides) for the specific application/service the server uses. Without this, the firewall will block the connection by default.
Why the other options are wrong
- A. Decryption is typically for inspecting traffic, not for enabling basic connectivity. While potentially needed for deep inspection later, it's not the primary reason for a lack of connectivity.
- B. An App-ID override is used when an application is misidentified or needs a custom signature; it's not related to initial connectivity issues for a known service.
- C. Source NAT is used for outbound connections from the server or internal network to the internet, not for inbound connections to the server.
NAT and Security Policy Interaction
On Palo Alto Networks firewalls, NAT rules translate IP addresses, but they do not implicitly allow traffic. A separate security policy rule is always required to explicitly permit traffic flow between zones, even after NAT has been applied.
- NAT = IP address translation.
- Security Policy = Traffic allowance/denial between zones.
- Both are required for inbound and outbound connections through the firewall.
Memory trick: Translate First, Then Permit.