Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A network administrator is troubleshooting an issue where users are unable to access an internal web application that is behind a Palo Alto Networks firewall. The firewall has a security policy allowing the traffic, but packet captures on the server show that the source IP address of the incoming connection is the firewall's egress interface IP, not the original client's IP. What type of NAT is most likely misconfigured or unexpectedly applied?

  1. ADestination NAT (DNAT)
  2. BNAT Overload (Port Address Translation).
  3. CSource NAT (SNAT) with dynamic IP.
  4. DStatic NAT (Bi-directional NAT).
Show answer & explanation

Correct answer: C. Source NAT (SNAT) with dynamic IP.

When the server receives traffic with the firewall's egress interface IP as the source, it indicates that Source NAT (SNAT) has been applied. Specifically, dynamic IP SNAT (or often NAT Overload, which is a type of dynamic SNAT) changes the client's source IP to an IP on the firewall itself (usually the egress interface IP) before forwarding the packet to the server. If this is not intended for an internal application, it's a misconfiguration.

Why the other options are wrong

  • A. DNAT changes the destination IP of inbound traffic, not the source IP of traffic reaching the server.
  • B. NAT Overload (PAT) is a form of dynamic SNAT. While it is a type of NAT that changes the source IP, the broader category of Source NAT is the primary cause of the observed symptom.
  • D. Static NAT typically maps a public IP to a private IP bi-directionally, but it usually preserves the original client source IP unless specifically configured with an additional SNAT.

Source NAT Identification

If a server receives traffic and the source IP address is the firewall's egress interface IP, it indicates that Source NAT (SNAT) has been applied to the traffic.

  • SNAT changes the source IP of packets.
  • Often used for outbound internet access.
  • Can be dynamic (PAT) or static (1:1).

Memory trick: NAT is a 'Name Changer' for IPs, check 'Source' if it's wrong.

More Troubleshoot questions