How to Route Multiple Internal Web Servers Through One External IP?
A security administrator needs to publish multiple application URLs that will run on different internal web servers but use only one external IP address. Which of the following is the best way for the administrator to achieve this goal?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests understanding of application-layer traffic routing versus network-layer address translation, where candidates often confuse reverse proxies with source NAT or destination port forwarding.
A reverse proxy enables administrators to expose multiple internal web applications through a single public IP by routing inbound traffic based on hostnames or URL paths while masking backend infrastructure.
Candidates frequently select Source NAT, mistaking it for the mechanism that hides internal addresses, but source NAT only modifies outbound traffic headers and cannot route inbound requests to different backend servers by URL.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A reverse proxy operates at the application layer and acts as an intermediary between clients and backend web servers. By listening on a single public IP address, it examines the requested hostname or URL path in incoming HTTP/HTTPS traffic and intelligently forwards requests to the appropriate internal server. This architecture not only fulfills the requirement to publish multiple application URLs through one external IP but also provides critical security benefits like SSL termination, load balancing, and IP address masking.Why the Other Options Are Wrong
Jump servers are dedicated bastion hosts designed for secure administrative access to restricted networks, not for routing web traffic. MAC filtering operates exclusively at Layer 2 to permit or block devices based on hardware addresses, making it completely irrelevant to IP-based web publishing. Source NAT translates private source addresses to a public IP for outbound communications, but it lacks the application-layer inspection required to route inbound requests to different backend servers based on URLs.Community Comment Notes
Learners consistently recognize that reverse proxies solve this exact scenario, with several noting how tools like NGINX effortlessly handle URL-based routing. Users who initially selected source NAT quickly realized it only handles outbound traffic direction and cannot parse HTTP host headers. Others highlighted the security advantages, pointing out that hiding backend server IPs makes it significantly harder for attackers to launch targeted DDoS campaigns. As salah112 noted, the reverse proxy approach is simply the best solution for achieving this specific publishing goal.Exam Strategy
When reviewing network architecture questions on the Security+ exam, always identify whether the scenario requires Layer 3/NAT functions or Layer 7/proxy functions before selecting an answer. Focus on keywords like 'publish URLs' or 'route traffic,' which strongly indicate an application-layer solution rather than basic address translation.
Frequently Asked Questions
Why isn't Source NAT the right choice for publishing internal web servers?
Source NAT only modifies outbound packet headers to hide internal IPs; it cannot route inbound HTTP requests to different backend servers based on URLs or hostnames.
How does a reverse proxy handle multiple domains on one IP?
It inspects the Host header in incoming HTTP/HTTPS requests and forwards traffic to the appropriate internal server, enabling virtual hosting without additional public IPs.