Exam PCNSA All QuestionsBrowse all questions from this exam
Question 167

Refer to the exhibit. An administrator is using DNAT to map two servers to a single public IP address. Traffic will be steered to the specific server based on the application, where Host A (10.1.1.100) receives HTTP traffic and Host B (10.1.1.101) receives SSH traffic.

Which two Security policy rules will accomplish this configuration? (Choose two.)

    Correct Answer: A, E

    For the configuration described, which directs HTTP traffic to Host A (10.1.1.100) and SSH traffic to Host B (10.1.1.101), the correct security policy rules need to match the destination addresses post-NAT and the appropriate ports for the services. Traffic directed to Host A using HTTP should allow web-browsing to 1.1.1.100 post-NAT, hence the rule Untrust to DMZ (1.1.1.100), web-browsing - Allow is correct. Similarly, for Host B, allowing ssh traffic to 1.1.1.100 post-NAT matches the rule Untrust to DMZ (1.1.1.100), ssh - Allow. These ensure the correct mapping and security policy for both types of traffic via Destination NAT.

Discussion
DlaEdu_ExOptions: AE

To define Destination, Security policy uses Post-NAT zone and Pre-NAT address

skaezOptions: DE

If we check DNAT, HTTP is for 1.1.1.100 so answer E And answer E is for the 2 DNAT and correct ports

JanhattalOptions: AE

A, E are correct

blu_gandalfOptions: DE

i think its D , E

blu_gandalf

i was worng sorry

ntirOptions: AE

A and E

OteslarOptions: AE

A and E are correct answers.

blahblah1234567890000

I dont understand how a could possibly be correct since the other server is supposed to get the SSH traffic.

blahblah1234567890000

Nevermind I misread the IP.