NGFW-ENGINEER · Question #44
Which two statements apply to configuring required security rules when setting up an IPSec tunnel between a Palo Alto Networks firewall and a third- party gateway? (Choose two.)
The correct answer is C. For incoming and outgoing traffic through the tunnel, separate rules must be created for each D. The IKE negotiation and IPSec/ESP packets are denied by default via the interzone default deny. Separate rules must be created for each direction: Palo Alto Networks firewalls enforce security policies based on traffic direction. To allow bidirectional communication through the IPSec tunnel, two separate rules are required - one for incoming and one for outgoing traffic…
Question
Which two statements apply to configuring required security rules when setting up an IPSec tunnel between a Palo Alto Networks firewall and a third- party gateway? (Choose two.)
Options
- AFor incoming and outgoing traffic through the tunnel, creating separate rules for each direction is
- BThe IKE negotiation and IPSec/ESP packets are allowed by default via the intrazone default allow
- CFor incoming and outgoing traffic through the tunnel, separate rules must be created for each
- DThe IKE negotiation and IPSec/ESP packets are denied by default via the interzone default deny
How the community answered
(32 responses)- A13% (4)
- B6% (2)
- C81% (26)
Explanation
Separate rules must be created for each direction: Palo Alto Networks firewalls enforce security policies based on traffic direction. To allow bidirectional communication through the IPSec tunnel, two separate rules are required - one for incoming and one for outgoing traffic. IKE negotiation and IPSec/ESP packets are denied by default: Palo Alto Networks firewalls use an interzone default deny policy, meaning that unless an explicit policy allows IKE (UDP 500/4500) and ESP (protocol 50) traffic, the firewall will block these packets, preventing tunnel establishment. Therefore, administrators must create explicit rules permitting IKE and IPSec/ESP traffic to the firewall's external interface.
Topics
Community Discussion
No community discussion yet for this question.