Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A company is migrating its internal mail server from a private IP address (10.0.0.10) to a new public IP address (203.0.113.5). External users need to access this mail server using the public IP. The Palo Alto Networks firewall must perform a static NAT to translate the public IP to the private IP. Which NAT policy configuration is correct?

  1. AOriginal Packet: Source Zone: Untrust, Destination Zone: Untrust, Destination Interface: ethernet1/1 (WAN), Service: any, Destination IP: 203.0.113.5. Translated Packet: Packet Type: Static IP, Destination Address: 10.0.0.10, Translated Port: no
  2. BOriginal Packet: Source Zone: Untrust, Destination Zone: Trust, Destination Interface: any, Service: any, Destination IP: 203.0.113.5. Translated Packet: Packet Type: Static IP, Destination Address: 10.0.0.10, Translated Port: no
  3. COriginal Packet: Source Zone: Trust, Destination Zone: Untrust, Destination Interface: any, Service: any, Destination IP: 10.0.0.10. Translated Packet: Packet Type: Static IP, Destination Address: 203.0.113.5, Translated Port: no
  4. DOriginal Packet: Source Zone: Untrust, Destination Zone: any, Destination Interface: any, Service: any, Destination IP: 203.0.113.5. Translated Packet: Packet Type: Dynamic IP and Port, Source Address: 10.0.0.10, Translated Port: yes
Show answer & explanation

Correct answer: B. Original Packet: Source Zone: Untrust, Destination Zone: Trust, Destination Interface: any, Service: any, Destination IP: 203.0.113.5. Translated Packet: Packet Type: Static IP, Destination Address: 10.0.0.10, Translated Port: no

This scenario describes a Destination NAT (D-NAT) where external traffic destined for a public IP (203.0.113.5) needs to be translated to a private internal IP (10.0.0.10). The original packet's destination zone will be 'Trust' (where the internal server resides) and the source zone will be 'Untrust' (external users). 'Static IP' for translation type and 'Destination Address' for the internal server IP are correct.

Why the other options are wrong

  • A. The 'Destination Zone: Untrust' in the original packet is incorrect; the traffic is ultimately destined for a server in the Trust zone.
  • C. The original packet's source and destination zones are reversed, and the destination IP is the private IP, not the public IP that external users would target.
  • D. Uses 'Dynamic IP and Port' and 'Source Address' translation, which is incorrect for a static Destination NAT. It also incorrectly specifies the translated address as the source.

Destination NAT (D-NAT)

Destination NAT (D-NAT) changes the destination IP address of packets passing through the firewall. It is commonly used to allow external access to internal servers.

  • D-NAT translates a public IP address to a private IP address for inbound connections.
  • The 'Original Packet' section defines the traffic *before* translation (inbound traffic to the public IP).
  • The 'Translated Packet' section defines the *result* of the translation (the internal server's private IP).

Memory trick: Original's the outside, Translated's the inside, zones guide the way.

More Security Policy Configuration questions