Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.
Which Zone Pair and Rule Type will allow a successful connection for a user on the Internet zone to a web server hosted on the DMZ zone? The web server is reachable using a Destination NAT policy in the Palo Alto Networks firewall. A.
Yes answer will be B, but the zone is correct DMZ is the post-nat destination zone;
the NAT rule will look like this:
source zone: Internet
destination zone: Internet
destination IP: public IP
destination translation: internal IP
the SEC rule will look like this:
source zone: Internet
destination zone: DMZ (post-NAT)
destination IP: Public IP (pre-NAT)
Which will make the traffic interzone.
Tip:
interzone vs intrazone -- I think of internet (global) vs intranet (local)
found it: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClomCAC
By default, all the traffic destined between two zones, regardless of being from the same zone or different zone, this applies the rule to all matching interzone and intrazone traffic in the specified source and destination zones.
The question asks "allow a successful connection" NAT policies do not allow traffic, Sec policies do.
upvoted 2 times
...
...
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
kraut
Highly Voted 2 years, 11 months agomtberdaan
2 years, 9 months agoMarshpillowz
Most Recent 2 months agoDenskyDen
1 year, 2 months agoTAKUM1y
1 year, 6 months agoGivemeMoney
2 years, 2 months agoGivemeMoney
2 years, 2 months agoketo3812
3 years agokraut
2 years, 11 months agovj77
2 years, 11 months agolildevil
9 months, 3 weeks ago