exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 501 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 501
Topic #: 1
[All PCNSE Questions]

A firewall engineer creates a destination static NAT rule to allow traffic from the internet to a webserver hosted behind the edge firewall. The pre-NAT IP address of the server is 153.6.12.10, and the post-NAT IP address is 192.168.10.10. Refer to the routing and interfaces information below.





What should the NAT rule destination zone be set to?

  • A. None
  • B. Inside
  • C. DMZ
  • D. Outside
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
jhoncena
Highly Voted 2 years ago
Answer should be D .. Outside to outside based on below : The destination zone in the NAT rule is determined after the route lookup of the destination IP address in the original packet (that is, the pre-NAT destination IP address). https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping
upvoted 15 times
[Removed]
1 year, 10 months ago
Good thinking you are correct, but check again the Routing table...
upvoted 4 times
...
jhoncena
2 years ago
I know both routing entries refer to Inside but the question is asking about the configuration part not the logical flow .. we need to configure outside > to > outside
upvoted 3 times
jhoncena
2 years ago
No Inside should be correct : )
upvoted 6 times
...
...
...
Knowledge33
Highly Voted 1 year, 11 months ago
Selected Answer: D
The answer is D, not B guys. We don't care about the routing table. When a paccket arrive on the outside Interface, The PAN checks first if there is a DNAT configured for this trafic, and If the trafic is allowed. Then It can proceed with the forwarding lookup (Routing table). That's why we need Outside>Outside NAT. B is totally wrong. There is no NAT on the Inside zone. FOrget the Routing table. It doesn't matter.
upvoted 12 times
Knowledge33
1 year, 10 months ago
My bad. The response is B
upvoted 10 times
Eluis007
1 year ago
A NAT rule is configured based on the zone associated with a pre-NAT IP address. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-policy-rules/nat-policy-overview
upvoted 4 times
scanossa
9 months, 2 weeks ago
Answer is D, a NAT rule is configured based on the zone associated with a pre-NAT IP address
upvoted 1 times
...
...
...
laroux
1 year, 11 months ago
> The destination zone in the NAT rule is determined after the route lookup of the destination IP address in the original packet (that is, the pre-NAT destination IP address). https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping
upvoted 1 times
...
...
Redheidoo
Most Recent 3 days, 23 hours ago
Selected Answer: D
Answer is D --> for destination NAT the Destination zone is always the same as the source zone
upvoted 1 times
...
DSBlue
2 months, 1 week ago
Selected Answer: B
It is B, the dest zone in the NAT rule must be that which the firewall has in its routing table for the pre-NAT dest address. I often check this with 'test routing fib-lookup vrouter vrname 1.1.1.1'
upvoted 1 times
...
Nkotrikadze
2 months, 3 weeks ago
Selected Answer: B
B is correct, tested in lab
upvoted 1 times
...
corpguy
2 months, 4 weeks ago
Selected Answer: B
The naming of the interfaces seems to be an attempt at a trick question.
upvoted 1 times
...
SCCUser
3 months, 2 weeks ago
Selected Answer: D
The destination zone in NAT rule is OUTSIDE, and the destination zone in security zone is INSIDE
upvoted 1 times
...
kewokil120
4 months, 2 weeks ago
Selected Answer: D
Answer is D. Refer to https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-networking-admin/nat/nat-configuration-examples/destination-nat-exampleone-to-one-mapping and the first image.
upvoted 2 times
...
Pretorian
5 months ago
Selected Answer: D
D is correct - Original packet for DNAT is untrust to untrust for zone.
upvoted 1 times
...
corpguy
5 months, 1 week ago
Selected Answer: D
Should be the Untrust or outside zone to/from regardless of the routing table.
upvoted 1 times
...
362c603
6 months, 2 weeks ago
Selected Answer: D
took and passed exam today. I answered Outside. DNAT Source and DST Zone should be PreNAT zone. I got few new questions that aren't here. If you at least study the concept and use this website as an extra study material, you should be good.
upvoted 2 times
...
Cosmonauta
7 months, 1 week ago
The correct answer should be B, first the packet could go through the firewall without nat, then the destination can be changed while it goes from false to internal, after nat the firewall knows the route to follow.
upvoted 1 times
...
thelittleyellowbirdie
8 months, 2 weeks ago
this was in my exam 09/08/2024
upvoted 2 times
...
Bau24
9 months, 1 week ago
Selected Answer: B
The pre-nat ip address is not on firewall itself and just routed to the inside network, so the Destination zone will be INSIDE
upvoted 2 times
...
Bau24
9 months, 1 week ago
Selected Answer: B
B -Inside
upvoted 1 times
...
scanossa
9 months, 1 week ago
This question was on my exam on July 23rd, 2024
upvoted 1 times
...
ATRRHMN
9 months, 3 weeks ago
Selected Answer: B
Pre-NAT IP is 153.6.12.10 Post-NAT zone is the one found after routing lookup which is "inside" --> next-hop for 192.168.10.0/24 is set to 192.168.1.2 (Eth1/2) which is in the inside zone.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago