PCNSA · Question #104
Which three interface deployment methods can be used to block traffic flowing through the Palo Alto Networks firewall? (Choose three.)
The correct answer is A. Layer 2 B. Virtual Wire D. Layer 3. The three Palo Alto Networks firewall interface deployment methods that allow for blocking traffic are Layer 2, Virtual Wire, and Layer 3 modes.
Question
Which three interface deployment methods can be used to block traffic flowing through the Palo Alto Networks firewall? (Choose three.)
Options
- ALayer 2
- BVirtual Wire
- CTap
- DLayer 3
- EHA
How the community answered
(43 responses)- A86% (37)
- C5% (2)
- E9% (4)
Why each option
The three Palo Alto Networks firewall interface deployment methods that allow for blocking traffic are Layer 2, Virtual Wire, and Layer 3 modes.
Layer 2 (L2) mode integrates the firewall transparently into a network segment, acting like a bridge. It can inspect and block traffic based on security policies without requiring IP address changes on devices.
Virtual Wire (VWire) mode is another transparent deployment option, functioning as an invisible segment. It allows the firewall to inspect and block traffic flowing between two network segments without routing or switching.
Tap mode allows the firewall to passively monitor network traffic by receiving a copy of it, but it cannot actively block or prevent traffic from passing through as it is out-of-band.
Layer 3 (L3) mode, or routing mode, positions the firewall as a router, actively routing traffic between different IP subnets. In this mode, it can fully inspect and block traffic based on security policies.
HA (High Availability) is a deployment feature that provides redundancy and fault tolerance for firewalls, not an interface deployment method for blocking traffic itself.
Concept tested: Palo Alto Networks Firewall Deployment Modes and Traffic Blocking Capabilities
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/getting-started/firewall-deployment-options
Topics
Community Discussion
No community discussion yet for this question.