PCNSE · Question #767
Why are external zones required to be configured on a Palo Alto Networks NGFW in an environment with multiple virtual systems?
The correct answer is C. To allow traffic between zones in different virtual systems without the traffic leaving the appliance. External zones are required in a multi-virtual system environment to enable internal traffic flow between different virtual systems within the same firewall appliance.
Question
Why are external zones required to be configured on a Palo Alto Networks NGFW in an environment with multiple virtual systems?
Options
- ATo allow traffic between zones in different virtual systems while the traffic is leaving the appliance
- BExternal zones are required because the same external zone can be used on different virtual
- CTo allow traffic between zones in different virtual systems without the traffic leaving the appliance
- DMultiple external zones are required in each virtual system to allow the communications between
How the community answered
(32 responses)- A3% (1)
- B6% (2)
- C88% (28)
- D3% (1)
Why each option
External zones are required in a multi-virtual system environment to enable internal traffic flow between different virtual systems within the same firewall appliance.
The primary purpose of external zones is to facilitate internal routing between VSYSs; while traffic might eventually leave the appliance, the 'while the traffic is leaving the appliance' clause misrepresents their core function for inter-VSYS communication.
Although external zones can represent shared networks, their *requirement* is driven by the need to enable communication between separate virtual systems, not merely their reusability across VSYSs.
External zones are a specific configuration element used in a multi-VSYS setup to route traffic logically between zones belonging to different virtual systems. This functionality enables inter-VSYS communication without the need for traffic to physically exit and re-enter the firewall appliance, maintaining internal segmentation.
Only a single external zone is typically required per virtual system to act as a gateway for inter-VSYS routing, not multiple external zones within each virtual system.
Concept tested: External zones in multi-VSYS environments
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/virtual-systems/configure-inter-vsys-routing/configure-external-zones-for-inter-vsys-routing.html
Topics
Community Discussion
No community discussion yet for this question.