Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationHard
A security technician needs to configure a security policy rule that allows internal users to access web applications hosted on servers in the DMZ. The policy must ensure that the source IP address of the internal users is preserved when reaching the DMZ servers for logging and auditing purposes on the servers. Which type of NAT policy should be associated with this security policy rule?
- ASource NAT (S-NAT) with Dynamic IP and Port (DIPP)
- BNo NAT
- CSource NAT (S-NAT) with Static IP
- DDestination NAT (D-NAT)
Show answer & explanationAnswer & explanation
Correct answer: B. No NAT
If the source IP address of internal users needs to be preserved when reaching DMZ servers, it means no Source NAT should be applied. Source NAT would translate the internal user's private IP to another IP (typically the firewall's egress interface or a pool of public IPs), thereby hiding the original source. Destination NAT is for inbound traffic, and S-NAT with DIPP/Static IP would still perform translation. Therefore, 'No NAT' is the correct choice to preserve the source IP.
Why the other options are wrong
- A. S-NAT with DIPP translates the source IP, which would prevent the DMZ servers from seeing the original internal user's IP.
- C. S-NAT with Static IP also translates the source IP, although to a fixed IP, still obscuring the original internal user's IP.
- D. Destination NAT (D-NAT) translates the *destination* IP for inbound traffic, not the source IP for outbound traffic from internal users.
No NAT for Source Preservation
When the original source IP address must be preserved through the firewall (e.g., for internal logging), no Source NAT policy should be applied to that traffic.
- Source NAT modifies the source IP.
- Destination NAT modifies the destination IP.
- No NAT means no IP address translation occurs.
Memory trick: No NAT: Keep the Source ID.