PCNSE · Question #762
A firewall engineer is managing a Palo Alto Networks NGFW which is not in line of any DHCP traffic. Which interface mode can the engineer use to generate Enhanced Application logs (EALs) for classifyi
The correct answer is D. Tap. To classify IoT devices and generate Enhanced Application Logs while passively receiving broadcast DHCP traffic without being in the data path, an engineer should use a Tap interface mode.
Question
A firewall engineer is managing a Palo Alto Networks NGFW which is not in line of any DHCP traffic. Which interface mode can the engineer use to generate Enhanced Application logs (EALs) for classifying IoT devices while receiving broadcast DHCP traffic?
Options
- AVirtual wire
- BLayer 3
- CLayer 2
- DTap
How the community answered
(66 responses)- A11% (7)
- B6% (4)
- C2% (1)
- D82% (54)
Why each option
To classify IoT devices and generate Enhanced Application Logs while passively receiving broadcast DHCP traffic without being in the data path, an engineer should use a Tap interface mode.
Virtual wire mode is an inline mode that bridges two interfaces, making the firewall part of the data path, which conflicts with 'not in line'.
Layer 3 mode involves IP routing and requires the firewall to be an active participant in the network path, making it an inline device.
Layer 2 mode operates as a transparent switch, also placing the firewall inline with the traffic flow, which is contrary to the requirement of 'not in line'.
A Tap interface operates in a passive listening mode, connected to a mirror or SPAN port, allowing the firewall to observe all network traffic, including broadcast DHCP, without being inline. This enables the firewall to generate Enhanced Application Logs (EALs) and classify IoT devices based on observed traffic without impacting network flow.
Concept tested: Tap interface for passive monitoring
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/getting-started/interface-types/tap-interface
Topics
Community Discussion
No community discussion yet for this question.