JN0-231 Exam QuestionsBrowse all questions from this exam

JN0-231 Exam - Question 2


You are assigned a project to configure SRX Series devices to allow connections to your webservers. The webservers have a private IP address, and the packets must use NAT to be accessible from the Internet. You do not want the webservers to initiate connections with external update servers on the Internet using the same IP address as customers use to access them.

Which two NAT types must be used to complete this project? (Choose two.)

Show Answer
Correct Answer: AD

To complete this project, you need to use Static NAT and Source NAT. Static NAT ensures that each webserver has a consistent, unchanging public IP address for inbound connections from the Internet, making sure the webservers are accessible. Source NAT is used for outbound connections initiated by the webservers to ensure they do not use the same IP address as the one used for incoming customer traffic. This way, the webservers can initiate connections with external update servers using a different public IP address.

Discussion

3 comments
Sign in to comment
fosi130Options: CD
Jul 9, 2023

CD as response

66dc178Options: AD
Jan 28, 2024

A. Static NAT D. Source NAT Static NAT is used to provide a consistent, unchanging public IP address for your webservers when accessed from the Internet, allowing inbound connections to them. Source NAT is used for outbound connections initiated by your webservers to external servers, allowing you to translate their private IP addresses to a different public IP address, ensuring that the IP used for incoming web traffic is not the same as the one used for the servers' outbound connections.

Fr3k411Options: CD
Feb 5, 2024

Static NAT defines a one-to-one mapping from one IP subnet to another IP subnet. The mapping includes destination IP address translation in one direction and source IP address translation in the reverse direction. From the NAT device, the original destination address is the virtual host IP address while the mapped-to address is the real host IP address. So not Static NAT