nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #9

In an active/active high availability (HA) configuration with two PA-Series firewalls, how do the firewalls use the HA3 interface?

The correct answer is A. To forward packets to the HA peer during session setup and asymmetric traffic flow. The HA3 interface, a Layer 2 link using MAC-in-MAC encapsulation, enables packet forwarding between active/active firewalls to handle asymmetric routing and ensure proper session setup when traffic arrives at the non-owner peer.

High Availability (HA) Configuration

Question

In an active/active high availability (HA) configuration with two PA-Series firewalls, how do the firewalls use the HA3 interface?

Options

  • ATo forward packets to the HA peer during session setup and asymmetric traffic flow
  • BTo exchange hellos, heartbeats, HA state information, and management plane synchronization
  • CTo synchronize sessions, forwarding tables, IPSec security associations, and ARP tables
  • DTo perform session cache synchronization among all HA peers having the same cluster ID

How the community answered

(22 responses)
  • A
    91% (20)
  • B
    5% (1)
  • D
    5% (1)

Explanation

The HA3 interface, a Layer 2 link using MAC-in-MAC encapsulation, enables packet forwarding between active/active firewalls to handle asymmetric routing and ensure proper session setup when traffic arrives at the non-owner peer.

Topics

#Palo Alto HA#Active/Active HA#HA3 Interface#Packet Forwarding

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice