PCNSE · Question #22
A host attached to Ethernet 1/4 cannot ping the default gateway. The widget on the dashboard shows Ethernet 1/1 and Ethernet 1/4 to be green. The IP address of Ethernet 1/1 is 192.168.1.7 and the IP…
The correct answer is A. No Zone has been configured on Ethernet 1/4. A host cannot ping its default gateway on the firewall if the egress interface lacks a configured security zone.
Question
A host attached to Ethernet 1/4 cannot ping the default gateway. The widget on the dashboard shows Ethernet 1/1 and Ethernet 1/4 to be green. The IP address of Ethernet 1/1 is 192.168.1.7 and the IP address of Ethernet 1/4 is 10.1.1.7. The default gateway is attached to Ethernet 1/1. A default route is properly configured. What can be the cause of this problem?
Options
- ANo Zone has been configured on Ethernet 1/4.
- BInterface Ethernet 1/1 is in Virtual Wire Mode.
- CDNS has not been properly configured on the firewall.
- DDNS has not been properly configured on the host.
How the community answered
(27 responses)- A81% (22)
- B4% (1)
- C11% (3)
- D4% (1)
Why each option
A host cannot ping its default gateway on the firewall if the egress interface lacks a configured security zone.
On a Palo Alto Networks firewall, all interfaces participating in traffic forwarding must be assigned to a security zone. If Ethernet 1/4 lacks a configured zone, the firewall will drop traffic originating from it, preventing the host from reaching its default gateway on Ethernet 1/1.
If Ethernet 1/1 were in Virtual Wire Mode, it would not have an IP address configured to act as a default gateway as described in the problem.
DNS configuration issues on the firewall affect name resolution, not the ability of a host to ping a direct IP address.
DNS configuration on the host affects name resolution for the host, but does not prevent it from pinging an IP address directly.
Concept tested: Palo Alto Networks Security Zones and interface configuration
Source: https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/networking/zones/configure-security-zones
Topics
Community Discussion
No community discussion yet for this question.