PCNSA · Question #281
If the firewall interface E1/1 is connected to a SPAN or mirror port, which interface type should E1/1 be configured as?
The correct answer is A. Tap. When a firewall interface is connected to a SPAN or mirror port for monitoring network traffic, it must be configured as a Tap interface.
Question
If the firewall interface E1/1 is connected to a SPAN or mirror port, which interface type should E1/1 be configured as?
Options
- ATap
- BVirtual Wire
- CLayer 2
- DLayer 3
How the community answered
(57 responses)- A88% (50)
- B7% (4)
- C4% (2)
- D2% (1)
Why each option
When a firewall interface is connected to a SPAN or mirror port for monitoring network traffic, it must be configured as a Tap interface.
A Tap interface on a Palo Alto Networks firewall is specifically designed for passive monitoring of network traffic by connecting to a switch's SPAN (Switched Port Analyzer) or mirror port without actively forwarding packets, allowing for threat detection and logging without disrupting traffic flow.
A Virtual Wire interface connects two network segments transparently for inline traffic inspection, which is not the purpose of connecting to a SPAN port for monitoring.
A Layer 2 interface operates like a switch port and participates in VLANs, requiring traffic to pass through the firewall, which is not suitable for passive monitoring via a SPAN port.
A Layer 3 interface functions as a router port with an IP address, participating in routing decisions and forwarding traffic, which is also not appropriate for passive monitoring from a SPAN port.
Concept tested: Interface types for passive monitoring (SPAN/mirror)
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/network/configure-interfaces/configure-a-tap-interface
Topics
Community Discussion
No community discussion yet for this question.