nerdexam
Palo_Alto_Networks

PCNSE · Question #263

A company wants to install a PA-3060 firewall between two core switches on a VLAN trunk link. They need to assign each VLAN to its own zone and assign untagged (native) traffic to its own zone. Which

The correct answer is B. Create V-Wire objects with two V-Wire subinterfaces and assign only a single VLAN ID to the. Virtual wire interfaces by default allow all untagged traffic. You can, however, use a virtual wire to connect two interfaces and configure either interface to block or allow traffic based on the virtual LAN (VLAN) tags. VLAN tag 0 indicates untagged traffic. You can also create

Submitted by amina.ke· Apr 18, 2026Deploy and Configure

Question

A company wants to install a PA-3060 firewall between two core switches on a VLAN trunk link. They need to assign each VLAN to its own zone and assign untagged (native) traffic to its own zone. Which option differentiates multiple VLANs into separate zones?

Options

  • ACreate V-Wire objects with two V-Wire interfaces and define a range of "0-4096" in the "Tag
  • BCreate V-Wire objects with two V-Wire subinterfaces and assign only a single VLAN ID to the
  • CCreate Layer 3 subinterfaces that are each assigned to a single VLAN ID and a common
  • DCreate VLAN objects for each VLAN and assign VLAN interfaces matching each VLAN ID.

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    72% (18)
  • C
    16% (4)
  • D
    4% (1)

Explanation

Virtual wire interfaces by default allow all untagged traffic. You can, however, use a virtual wire to connect two interfaces and configure either interface to block or allow traffic based on the virtual LAN (VLAN) tags. VLAN tag 0 indicates untagged traffic. You can also create multiple subinterfaces, add them into different zones, and then classify traffic according to a VLAN tag or a combination of a VLAN tag with IP classifiers (address, range, or subnet) to apply granular policy control for specific VLAN tags or for VLAN tags from a specific source IP address, range, or subnet. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure- interfaces/virtual-wire-interfaces/virtual-wire-subinterfaces

Topics

#V-Wire#VLAN Subinterfaces#Security Zones#Transparent Deployment

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice