Palo Alto Networks Certified Network Security Administrator (PCNSA)Security Policy ConfigurationMedium

A security engineer is configuring a NAT policy on a Palo Alto Networks firewall to allow internal users to access external resources using a pool of public IP addresses. The requirement specifies that outbound connections should use any available IP address from the pool, and subsequent return traffic should correctly map back to the original internal user. Which NAT type and translation method should be configured?

  1. AStatic NAT with a 1:1 mapping
  2. BDestination NAT (D-NAT)
  3. CDynamic IP and Port (DIPP) Source NAT
  4. DDynamic IP Source NAT
Show answer & explanation

Correct answer: C. Dynamic IP and Port (DIPP) Source NAT

To allow multiple internal users to share a pool of public IP addresses for outbound internet access, and ensure return traffic is correctly routed, Dynamic IP and Port (DIPP) Source NAT is the most suitable method. DIPP uses both IP addresses and port numbers for translation, enabling many-to-one or many-to-few mappings.

Why the other options are wrong

  • A. Static NAT (1:1) maps one private IP to one public IP, which is inefficient for a pool of users and does not allow sharing.
  • B. Destination NAT (D-NAT) is used for inbound connections to internal servers, not for outbound user access.
  • D. Dynamic IP Source NAT without port translation would map one private IP to one public IP from the pool for the duration of the session, but wouldn't allow multiple users to share a single public IP effectively for concurrent connections without quickly exhausting the pool.

Dynamic IP and Port (DIPP) Source NAT

DIPP Source NAT translates both the source IP address and source port of outbound connections, allowing multiple internal hosts to share a limited pool of public IP addresses.

  • Many-to-one or many-to-few mapping.
  • Uses both IP and port translation.
  • Commonly used for outbound internet access from internal networks.
  • Preserves session state for return traffic.

Memory trick: NAT is like a postal service: it changes the 'return address' (Source NAT) or the 'destination address' (Destination NAT) of packets.

More Security Policy Configuration questions