PrepAway - Latest Free Exam Questions & Answers

what could be the source address/port of the packet arriving at host Certkiller B?

If Certkiller A initiates a Web browsing session with Certkiller B, and the Trust interface of the 5XT is in NAT mode, what could be the source address/port of the packet arriving at host Certkiller B?

PrepAway - Latest Free Exam Questions & Answers

A.
10.0.0.5/80

B.
10.0.0.5/1099

C.
10.0.0.1/1024

D.
20.0.0.1/1024

E.
1.1.1.250/1024

Explanation:
When an ingress interface (10.0.0.1) is in Network Address Translation (NAT) mode, the NetScreen device, acting like a Layer 3 switch (or router), translates two components in the header of an outgoing IP packet destined for the Untrust zone: its source IP address and source port number. The NetScreen device replaces the source IP address of the originating host with the IP address of the Untrust zone interface (1.1.1.250). Also, it replaces the source port number with another random port number generated by the NetScreen device. The port numbers 1 to 1023 are reserved for well known port numbers, so the next available port number could be 1024.


Leave a Reply