QuestionQ46

Network Address Translation

You must ensure that the security policy is correctly configured for a flow involving both source NAT and destination NAT.

In this scenario, which two source and destination address match conditions are valid?

Choose two
  • A post-NAT destination address
  • B pre-NAT source address
  • C post-NAT source address
  • D pre-NAT destination address
Explanation

Palo Alto Networks security policy rules match traffic using the original, pre-NAT source and destination IP addresses. NAT translation occurs after the security-policy evaluation for address matching, although the policy uses post-NAT zones.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!