nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #20

An NGFW engineer is establishing bidirectional connectivity between the accounting virtual system (VSYS) and the marketing VSYS. The traffic needs to transition between zones without leaving the…

The correct answer is C. Enable the "allow inter-VSYS traffic" option in both external zone configurations. External zones in Palo Alto firewalls require explicitly enabling "Allow traffic from other VSYS" (or similar inter-VSYS traffic allowance) in their zone configurations to permit bidirectional flow between VSYS without physical external routing, even when VSYS visibility…

Implement and Manage Virtual Systems

Question

An NGFW engineer is establishing bidirectional connectivity between the accounting virtual system (VSYS) and the marketing VSYS. The traffic needs to transition between zones without leaving the firewall (no external physical connections). The interfaces for each VSYS are assigned to separate virtual routers (VRs), and inter-VR static routes have been configured. An external zone has been created correctly for each VSYS. Security policies have been added to permit the desired traffic between each zone and its respective external zone. However, the desired traffic is still unable to successfully pass from one VSYS to the other in either direction. Which additional configuration task is required to resolve this issue?

Options

  • ACreate a transit VSYS and route all inter-VSYS traffic through it.
  • BAdd each VSYS to the list of visible virtual systems of the other VSYS.
  • CEnable the "allow inter-VSYS traffic" option in both external zone configurations.
  • DCreate Security policies to allow the traffic between the two external zones.

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    6% (1)
  • C
    76% (13)
  • D
    12% (2)

Explanation

External zones in Palo Alto firewalls require explicitly enabling "Allow traffic from other VSYS" (or similar inter-VSYS traffic allowance) in their zone configurations to permit bidirectional flow between VSYS without physical external routing, even when VSYS visibility, policies, and inter- VR routes are already configured. Why VSYS Visibility Alone Fails While adding VSYS to each other's visible list enables awareness of external zones across VSYS boundaries, traffic still drops unless the external zones themselves permit inter-VSYS traversal, as zones enforce isolation by default beyond mere visibility.

Topics

#Virtual Systems (VSYS)#Inter-VSYS Communication#Zone Configuration#Routing

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice