Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium
A security engineer is troubleshooting an issue where users are unable to access a newly deployed internal web application hosted on a server with a private IP address (192.168.10.50). The application is accessed via a public IP address (203.0.113.10) configured on the firewall. Users from the internet are reporting a connection timeout. Which type of NAT policy is most likely misconfigured or missing?
- ASource NAT (S-NAT)
- BDestination NAT (D-NAT)
- CU-turn NAT
- DDynamic IP and Port (DIPP) NAT
Show answer & explanationAnswer & explanation
Correct answer: B. Destination NAT (D-NAT)
When external users try to access an internal server using a public IP address, the firewall must translate the public destination IP to the server's private IP. This translation is performed by Destination NAT (D-NAT). A connection timeout suggests the firewall isn't correctly forwarding the traffic to the internal server.
Why the other options are wrong
- A. Source NAT (S-NAT) translates the source IP of internal users when they access external resources, which is not the issue here.
- C. U-turn NAT (or Hairpin NAT) is used when internal users access an internal server using its public IP, which is not the scenario described (users from the internet).
- D. Dynamic IP and Port (DIPP) NAT is a form of S-NAT where multiple internal IPs share one or a few public IPs, not relevant for incoming connections.
Destination NAT (D-NAT)
Destination NAT translates the destination IP address of an incoming packet from a public IP to a private IP, allowing external users to access internal servers.
- Used for inbound connections to internal services.
- Changes the destination IP header of the packet.
- Requires a security policy rule to allow the traffic after translation.
Memory trick: D-NAT: Directing Inbound Destinations.