JNCIA-SEC Exam QuestionsBrowse all questions from this exam

JNCIA-SEC Exam - Question 16


Your ISP gives you an IP address of 203.0.113.0/27 and informs you that your default gateway is 203.0.113.1. You configure destination NAT to your internal server, but the requests sent to the webserver at 203.0.113.5 are not arriving at the server.

In this scenario, which two configuration features need to be added? (Choose two.)

Show Answer
Correct Answer: BC

In this scenario, you need to configure a security policy and proxy-ARP. Security policy is necessary to allow the incoming traffic through the firewall to reach the internal server. Proxy-ARP is required to enable the device to respond to ARP requests for the public IP address mapped to the internal server. These configurations are essential to resolve the issue of requests not arriving at the internal server when using destination NAT.

Discussion

1 comment
Sign in to comment
CradicalOptions: BC
Aug 4, 2024

Security Policy (B): To allow the incoming traffic through the firewall to reach the internal server. Proxy-ARP (C): To enable the SRX device to respond to ARP requests for the public IP address mapped to the internal server. These two configurations should address the issue of requests not arriving at your internal server when using destination NAT.