nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #44

Which two statements apply to configuring required security rules when setting up an IPSec tunnel between a Palo Alto Networks firewall and a third- party gateway? (Choose two.)

The correct answer is C. For incoming and outgoing traffic through the tunnel, separate rules must be created for each D. The IKE negotiation and IPSec/ESP packets are denied by default via the interzone default deny. Separate rules must be created for each direction: Palo Alto Networks firewalls enforce security policies based on traffic direction. To allow bidirectional communication through the IPSec tunnel, two separate rules are required - one for incoming and one for outgoing traffic…

Security Policy Configuration

Question

Which two statements apply to configuring required security rules when setting up an IPSec tunnel between a Palo Alto Networks firewall and a third- party gateway? (Choose two.)

Options

  • AFor incoming and outgoing traffic through the tunnel, creating separate rules for each direction is
  • BThe IKE negotiation and IPSec/ESP packets are allowed by default via the intrazone default allow
  • CFor incoming and outgoing traffic through the tunnel, separate rules must be created for each
  • DThe IKE negotiation and IPSec/ESP packets are denied by default via the interzone default deny

How the community answered

(32 responses)
  • A
    13% (4)
  • B
    6% (2)
  • C
    81% (26)

Explanation

Separate rules must be created for each direction: Palo Alto Networks firewalls enforce security policies based on traffic direction. To allow bidirectional communication through the IPSec tunnel, two separate rules are required - one for incoming and one for outgoing traffic. IKE negotiation and IPSec/ESP packets are denied by default: Palo Alto Networks firewalls use an interzone default deny policy, meaning that unless an explicit policy allows IKE (UDP 500/4500) and ESP (protocol 50) traffic, the firewall will block these packets, preventing tunnel establishment. Therefore, administrators must create explicit rules permitting IKE and IPSec/ESP traffic to the firewall's external interface.

Topics

#IPSec VPN#Security Policies#Palo Alto Firewall#Network Zones

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice