pcnsa question 158 discussion

View all Palo Alto Networks Certified Network Security Administrator here
back to palo-alto-networks forum

Question 158

Which statement is true regarding NAT rules?

  • A. Translation of the IP address and port occurs before security processing.
  • B. Firewall supports NAT on Layer 3 interfaces only.
  • C. Static NAT rules have precedence over other forms of NAT.
  • D. NAT rules are processed in order from top to bottom.
Answer:

a

User Votes:
A
50%
B
50%
C
50%
D 1 votes
50%
Discussions
0 / 1000
sara123
1 month, 3 weeks ago

The firewall evaluates the rules in order from the top down. Once a packet matches the criteria of a single NAT rule, the packet is not subjected to additional NAT rules.
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/nat/nat-policy-rules/nat-policy-overview