PCNSE · Question #460
A user's traffic traversing a Palo Alto Networks NGFW sometimes can reach How can the firewall be configured automatically disable the PBF rule if the next hop goes down?
The correct answer is A. Create and add a monitor profile with an action of fail over in the PBF rule in question. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/network/network- network-profiles/network-network-profiles-monitor A monitor profile is used to monitor IPSec tunnels and to monitor a next-hop device for policy- based forwarding (PBF) rules. In both cases,
Question
A user's traffic traversing a Palo Alto Networks NGFW sometimes can reach How can the firewall be configured automatically disable the PBF rule if the next hop goes down?
Options
- ACreate and add a monitor profile with an action of fail over in the PBF rule in question
- BCreate and add a monitor profile with an action of wait recover in the PBF rule in question
- CConfigure path monitoring for the next hop gateway on the default route in the virtual router
- DEnable and configure a link monitoring profile for the external interface of the firewall
How the community answered
(49 responses)- A76% (37)
- B4% (2)
- C6% (3)
- D14% (7)
Explanation
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/network/network- network-profiles/network-network-profiles-monitor A monitor profile is used to monitor IPSec tunnels and to monitor a next-hop device for policy- based forwarding (PBF) rules. In both cases, the monitor profile is used to specify an action to take when a resource (IPSec tunnel or next-hop device) becomes unavailable. wait-recover - Wait for the tunnel to recover; do not take additional action. Packets will continue to be sent according to the PBF rule. fail-over - Traffic will fail over to a backup path, if one is available. The firewall uses routing table lookup to determine routing for the duration of this session.
Topics
Community Discussion
No community discussion yet for this question.