Palo Alto Networks Certified Network Security Engineer (PCNSE)Manage and OperateHard

A company is implementing a new external web server in their DMZ and needs to allow inbound HTTPS access from the internet. The external IP address of the web server is 203.0.113.10 and its internal IP is 10.0.0.10. The firewall must perform Destination NAT to translate the external IP to the internal IP. Which configuration is correct for the Destination NAT rule?

  1. AOriginal Packet: Source Zone=Untrust, Destination Zone=Trust, Destination IP=10.0.0.10. Translated Packet: Destination IP=203.0.113.10.
  2. BOriginal Packet: Source Zone=Untrust, Destination Zone=DMZ, Destination IP=203.0.113.10. Translated Packet: Destination IP=10.0.0.10.
  3. COriginal Packet: Source Zone=Untrust, Destination Zone=Untrust, Destination IP=203.0.113.10. Translated Packet: Destination IP=10.0.0.10.
  4. DOriginal Packet: Source Zone=Untrust, Destination Zone=DMZ, Destination IP=10.0.0.10. Translated Packet: Destination IP=203.0.113.10.
Show answer & explanation

Correct answer: B. Original Packet: Source Zone=Untrust, Destination Zone=DMZ, Destination IP=203.0.113.10. Translated Packet: Destination IP=10.0.0.10.

For Destination NAT, the 'Original Packet' refers to the packet as it arrives at the firewall. So, the destination IP will be the public IP (203.0.113.10), and the destination zone will be the zone where the internal server resides (DMZ). The 'Translated Packet' shows the change: the destination IP becomes the internal IP (10.0.0.10).

Why the other options are wrong

  • A. The Original Packet's Destination IP should be the public IP (203.0.113.10), not the internal. The Destination Zone should be DMZ, not Trust.
  • C. The Original Packet's Destination Zone should be DMZ (where the server is, after NAT), not Untrust. The Translated Packet's Destination IP is correct.
  • D. The Original Packet's Destination IP should be the public IP (203.0.113.10), not the internal one.

Palo Alto Networks Destination NAT

A NAT type that modifies the destination IP address of incoming packets, typically used to translate public IP addresses to private internal server IP addresses.

  • Applied to traffic entering the firewall from an external network.
  • Original Packet fields reflect the incoming packet's headers.
  • Translated Packet fields show the modifications made by the NAT rule.

Memory trick: Original is public view, Translated is private reality.

More Manage and Operate questions