nerdexam
Palo_Alto_Networks

PCNSE · Question #22

A host attached to Ethernet 1/4 cannot ping the default gateway. The widget on the dashboard shows Ethernet 1/1 and Ethernet 1/4 to be green. The IP address of Ethernet 1/1 is 192.168.1.7 and the IP…

The correct answer is A. No Zone has been configured on Ethernet 1/4. A host cannot ping its default gateway on the firewall if the egress interface lacks a configured security zone.

Submitted by tarun92· Apr 18, 2026Configuration Troubleshooting

Question

A host attached to Ethernet 1/4 cannot ping the default gateway. The widget on the dashboard shows Ethernet 1/1 and Ethernet 1/4 to be green. The IP address of Ethernet 1/1 is 192.168.1.7 and the IP address of Ethernet 1/4 is 10.1.1.7. The default gateway is attached to Ethernet 1/1. A default route is properly configured. What can be the cause of this problem?

Options

  • ANo Zone has been configured on Ethernet 1/4.
  • BInterface Ethernet 1/1 is in Virtual Wire Mode.
  • CDNS has not been properly configured on the firewall.
  • DDNS has not been properly configured on the host.

How the community answered

(27 responses)
  • A
    81% (22)
  • B
    4% (1)
  • C
    11% (3)
  • D
    4% (1)

Why each option

A host cannot ping its default gateway on the firewall if the egress interface lacks a configured security zone.

ANo Zone has been configured on Ethernet 1/4.Correct

On a Palo Alto Networks firewall, all interfaces participating in traffic forwarding must be assigned to a security zone. If Ethernet 1/4 lacks a configured zone, the firewall will drop traffic originating from it, preventing the host from reaching its default gateway on Ethernet 1/1.

BInterface Ethernet 1/1 is in Virtual Wire Mode.

If Ethernet 1/1 were in Virtual Wire Mode, it would not have an IP address configured to act as a default gateway as described in the problem.

CDNS has not been properly configured on the firewall.

DNS configuration issues on the firewall affect name resolution, not the ability of a host to ping a direct IP address.

DDNS has not been properly configured on the host.

DNS configuration on the host affects name resolution for the host, but does not prevent it from pinging an IP address directly.

Concept tested: Palo Alto Networks Security Zones and interface configuration

Source: https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/networking/zones/configure-security-zones

Topics

#Security Zones#Interface Configuration#Connectivity Troubleshooting#Palo Alto Firewall Basics

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice