PrepAway - Latest Free Exam Questions & Answers

Original “web_public_IP?

You just installed a new Web server in the DMZ that must be reachable from the Internet. You
create a manual Static NAT rule as follows:
SourcE. Any || Destination: web_public_IP || ServicE. Any || Translated SourcE. original ||
Translated Destination: web_private_IP || ServicE. Original
“web_public_IP? is the node object that represents the new Web server’s public IP address.
“web_private_IP? is the node object that represents the new Web site’s private IP address. You
enable all settings from Global Properties > NAT.
When you try to browse the Web server from the Internet you see the error “page cannot be
displayed?. Which of the following is NOT a possible reason?

PrepAway - Latest Free Exam Questions & Answers

A.
There is no Security Policy defined that allows HTTP traffic to the protected Web server.
B. There is no ARP table entry for the protected Web server’s public IP address.

C.
There is no route defined on the Security Gateway for the public IP address to the Web server’s
private IP address.

D.
There is no NAT rule translating the source IP address of packets coming from the protected
Web server.

12 Comments on “Original “web_public_IP?

      1. Bluebeard says:

        Because question asks which is NOT a possible reason, and static NAT rule has been described in the question. Source IP of web server does not need translation when “you try to browse the Web server from the Internet”, and destination NAT rule is handling the traffic in and out….




        0



        0
  1. Rafa says:

    Should be C. If all NAT settings are selected, you have enabled “Translate on client side” so you don’t need a route in the gateway for the public address for it to work.




    0



    0
  2. SB says:

    C is the answer, once you select translation on client side in global properties, there is no need to have a static route for the packets reaching the natted IP to reach the private address.

    All other options are possible reasons for why the access didn’t work.




    0



    0
  3. Alan Follmann says:

    C is the answer

    A) a rule is necessary
    B) arp entry is necessary for manual nat
    D) bidirectional nat is not activated in manual nat. When the server reply to the request, the reply need to have its source IP address translated to go to the internet.




    0



    0

Leave a Reply