exam questions

Exam 300-206 All Questions

View all questions & answers for the 300-206 exam

Exam 300-206 topic 1 question 154 discussion

Actual exam question from Cisco's 300-206
Question #: 154
Topic #: 1
[All 300-206 Questions]

SIMULATION -
You are a network security engineer for the Secure-X network. You have been tasked with implementing dynamic network object NAT with PAT on a Cisco ASA.
You must configure the Cisco ASA such that the source IP addresses of all internal hosts are translated to a single IP address (using different ports) when the internal hosts access the Internet.
To successfully complete this activity, you must perform the following tasks:
✑ Use the Cisco ASDM GUI on the Admin PC to configure dynamic network object NAT with PAT using the following parameters:
✑ Network object name: Internal-Networks
✑ IP subnet: 10.10.0.0/16
✑ Translated IP address: 192.0.2.100
✑ Source interface: inside
✑ Destination interface: outside
NOTE: The object (TRANSLATED-INSIDE-HOSTS) for this translated IP address has already been created for your use in this activity.
NOTE: Not all ASDM screens are active for this exercise.
NOTE: Login credentials are not needed for this simulation.
✑ In the Cisco ASDM, display and view the auto-generated NAT rule.
✑ From the Employee PC, generate traffic to SP-SRV by opening a browser and navigating to http://sp-srv.sp.public.
✑ From the Guest PC, generate traffic to SP-SRV by opening a browser and navigating to http://sp-srv.sp.public.
✑ At the CLI of the Cisco ASA, display your NAT configuration. You should see the configured policy and statistics for translated packets.
✑ At the CLI of the Cisco ASA, display the translation table. You should see dynamic translations for the Employee PC and the Guest PC. Both inside IP addresses translate to the same IP address, but using different ports.
You have completed this exercise when you have configured and successfully tested dynamic network object NAT with PAT.




Show Suggested Answer Hide Answer
Suggested Answer: See the explanation for detailed answer to this sim question
First, click on Add Network Objects on the Network Objects/Groups tab and fill in the information as shown below:

Then, use the advanced tab and configure it as shown below:

Then hit OK, OK again, Apply, and then Send when prompted. You can verify using the instructions provided in the question.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Netman
5 years, 5 months ago
Yes, I meant I agree with you Throttlerainer about the sub-nets being different!
upvoted 2 times
...
Netman
5 years, 5 months ago
Yes, and also are we not supposed to use the TRANSLATED-INSIDE-HOSTS already configured?
upvoted 2 times
...
Throttlerainer
5 years, 6 months ago
✑ IP subnet: 10.10.0.0/16 at solution network object is 10.0.0.0 255.255.0.0
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...