問題文
A published server on an inside network is reached by outside clients through a translation of the destination address. The design asks for the steady pairing that persistent NAT gives, and an engineer has been told to write it under the rules for the destination. What should the engineer report back?
選択肢
- It can be written there once the inside server has sent one packet of its own toward the outside, because that one packet is what opens the pairing, even for the rules that sit on the other side.
- It cannot be written there at all, because the pairings are built from the sessions that leave the inside network for the outside, so the feature belongs with the rules for the source and with the action of one of those rules.
- It can be written there, but only where the action of the rule names a pool that leaves the ports alone, because the pairing has to own one port of its own on each of the two sides of the firewall.
- It can be written there as long as the type that names the outside host is chosen, because that one type is the one meant for the sessions that arrive from the outside, rather than for the sessions that leave.