NGFW-ENGINEER · Question #7
For which two purposes is an IP address configured on a tunnel interface? (Choose two.)
The correct answer is A. Use of dynamic routing protocols B. Tunnel monitoring. Tunnel interfaces on PAN-OS do NOT require an IP address for basic IPSec VPN operation - traffic is encapsulated and forwarded based on routing and Proxy IDs alone. However, there are two specific scenarios that require an IP address on the tunnel interface: (A) Dynamic routing…
Question
For which two purposes is an IP address configured on a tunnel interface? (Choose two.)
Options
- AUse of dynamic routing protocols
- BTunnel monitoring
- CUse of peer IP
- DRedistribution of User-ID
How the community answered
(23 responses)- A91% (21)
- C4% (1)
- D4% (1)
Explanation
Tunnel interfaces on PAN-OS do NOT require an IP address for basic IPSec VPN operation - traffic is encapsulated and forwarded based on routing and Proxy IDs alone. However, there are two specific scenarios that require an IP address on the tunnel interface: (A) Dynamic routing protocols such as OSPF, BGP, or EIGRP require a source IP address to form neighbor adjacencies and exchange routing updates over the tunnel. Without an IP on the tunnel interface, dynamic routing cannot establish. (B) Tunnel monitoring uses ICMP echo requests (pings) to verify that the tunnel is passing traffic end-to-end. The firewall needs a source IP on the tunnel interface to send and receive these monitoring pings. Options C and D are incorrect: the peer IP is configured in the IKE gateway settings, not derived from the tunnel interface IP, and User-ID redistribution does not require a tunnel interface IP.
Topics
Community Discussion
No community discussion yet for this question.