PCNSE · Question #569
A firewall administrator wants to have visibility on one segment of the company network. The traffic on the segment is routed on the Backbone switch. The administrator is planning to apply Security…
The correct answer is C. Configure vwire interfaces for segment X on the firewall. As it specifically states in the question that security rules will be applied, VWire is the only method that allows this without making any IP address changes. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure- interfaces/virtual-wire-interfaces
Question
A firewall administrator wants to have visibility on one segment of the company network. The traffic on the segment is routed on the Backbone switch. The administrator is planning to apply Security rules on segment X after getting the visibility. There is already a PAN-OS firewall used in L3 mode as an internet gateway, and there are enough system resources to get extra traffic on the firewall. The administrator needs to complete this operation with minimum service interruptions and without making any IP changes. What is the best option for the administrator to take?
Options
- AConfigure the TAP interface for segment X on the firewall
- BConfigure a Layer 3 interface for segment X on the firewall.
- CConfigure vwire interfaces for segment X on the firewall.
- DConfigure a new vsys for segment X on the firewall.
How the community answered
(22 responses)- A5% (1)
- B14% (3)
- C77% (17)
- D5% (1)
Explanation
As it specifically states in the question that security rules will be applied, VWire is the only method that allows this without making any IP address changes. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure- interfaces/virtual-wire-interfaces
Topics
Community Discussion
No community discussion yet for this question.