問題文
A company publishes a server with a destination NAT rule. Internal users who reach the same server by its public name are then found to need an extra rule. What is the reason such a case needs separate treatment?
選択肢
- Because the internal request leaves and returns through the same zone, so the translation and the security rule have to be written for that path as well.
- Because internal users cannot be identified by name so that the rule has to fall back on the source address of each of them.
- Because destination NAT is evaluated after the security policy so that the rule has to name the private address of the server.
- Because the destination NAT rule only applies to sessions that arrive on the interface that carries the public address, and internal users arrive on a different interface, which means the public name has to be resolved to the private address instead.