Exam PCNSA All QuestionsBrowse all questions from this exam
Question 252

Which statement is true regarding NAT rules?

    Correct Answer: D

    NAT rules are processed in order from top to bottom. This means that the firewall evaluates each rule starting from the top of the list and moves downwards until a matching rule is found. This ensures that the most specific or highest priority rules are applied first.

Discussion
davidmdlp85Option: D

- The firewall evaluates the rules in order from the top down - Static NAT rules do not have precedence over other forms of NAT. - Upon ingress, the firewall inspects the packet and does a route lookup to determine the egress interface and zone. Then the firewall determines if the packet matches one of the NAT rules that have been defined, based on source and/or destination zone. It then evaluates and applies any security policies that match the packet based on the original (pre-NAT) source and destination addresses, but the post-NAT zones. Finally, upon egress, for a matching NAT rule, the firewall translates the source and/or destination address and port numbers. - FW supports NAT also on Vwire interfaces. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/nat/nat-policy-rules/nat-policy-overview

Vijay_75Option: A

A and D are true as below: 1. the NAT rules are processed first before the security rules (https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVHCA0) 2. the NAT rules are processed from top down (https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/nat/nat-policy-rules/nat-policy-overview)

OhEmGee

A is not the answer as NAT "evaluation" happens before Sec Policy but actual "translation" happens after Sec Pol evaluation. Answer is D

PunkSpOption: D

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/nat/nat-policy-rules/nat-policy-overview

sguerouate

Agree, A is impossible to use Answer D !

plasticpurduestridentOption: A

So in the actual exam do you pick A or D? Where do these (wrong) answers come from? The actual exam?

MarkGrootaartsOption: D

Answer is D

DatITGuyTho1337Option: D

Answer is D, but B is also viable!!

N1KH1L

in Vwire mode there is a nat capability so do not think B is viable

LetsDiscuss23Option: D

Answer is D

khaled_ellaboudyOption: D

D is the most relevent answer and has only one meaning.