Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A security engineer is troubleshooting an issue where users are unable to access a newly deployed internal web application hosted on a server with a private IP address (192.168.10.50). The application is accessed via a public IP address (203.0.113.10) configured on the firewall. Users from the internet are reporting a connection timeout. Which type of NAT policy is most likely misconfigured or missing?

  1. ASource NAT (S-NAT)
  2. BDestination NAT (D-NAT)
  3. CU-turn NAT
  4. DDynamic IP and Port (DIPP) NAT
Show answer & explanation

Correct answer: B. Destination NAT (D-NAT)

When external users try to access an internal server using a public IP address, the firewall must translate the public destination IP to the server's private IP. This translation is performed by Destination NAT (D-NAT). A connection timeout suggests the firewall isn't correctly forwarding the traffic to the internal server.

Why the other options are wrong

  • A. Source NAT (S-NAT) translates the source IP of internal users when they access external resources, which is not the issue here.
  • C. U-turn NAT (or Hairpin NAT) is used when internal users access an internal server using its public IP, which is not the scenario described (users from the internet).
  • D. Dynamic IP and Port (DIPP) NAT is a form of S-NAT where multiple internal IPs share one or a few public IPs, not relevant for incoming connections.

Destination NAT (D-NAT)

Destination NAT translates the destination IP address of an incoming packet from a public IP to a private IP, allowing external users to access internal servers.

  • Used for inbound connections to internal services.
  • Changes the destination IP header of the packet.
  • Requires a security policy rule to allow the traffic after translation.

Memory trick: D-NAT: Directing Inbound Destinations.

More Security Policy Configuration questions