PCNSE · Question #846
A customer requires that virtual systems with separate virtual routers can communicate with one another within a Palo Alto Networks firewall. In addition to confirming Security policies, which three…
The correct answer is B. External zones with the virtual systems added C. Route added with next hop next-vr by using the VR configured in the virtual system D. Layer 3 zones for the virtual systems that need to communicate. To enable communication between virtual systems with separate virtual routers, administrators must configure Layer 3 zones, use 'next-vr' routing, and define appropriate security zones.
Question
A customer requires that virtual systems with separate virtual routers can communicate with one another within a Palo Alto Networks firewall. In addition to confirming Security policies, which three configurations will accomplish this goal? (Choose three)
Options
- ARoute added with next hop set to "none" and using the interface of the virtual systems that need
- BExternal zones with the virtual systems added
- CRoute added with next hop next-vr by using the VR configured in the virtual system
- DLayer 3 zones for the virtual systems that need to communicate
How the community answered
(18 responses)- A22% (4)
- B78% (14)
Why each option
To enable communication between virtual systems with separate virtual routers, administrators must configure Layer 3 zones, use 'next-vr' routing, and define appropriate security zones.
A route with a next hop set to 'none' typically indicates a blackhole route or a directly connected network, which would not facilitate routing traffic between separate virtual routers on different virtual systems.
Configuring appropriate security zones, which can be thought of as external zones when they bridge communication between different virtual systems or facilitate inter-vsys routing, is crucial for defining the security context and allowing policy enforcement between virtual systems.
Implementing routes with a next hop type of 'next-vr' that explicitly specifies the target virtual router is essential for directing traffic from one virtual system's router to another virtual system's router within the same firewall. This enables inter-vsys routing.
Configuring Layer 3 zones for the interfaces used by the virtual systems is fundamental, as these zones define the security boundaries and are necessary for applying security policies to traffic flowing between the virtual systems' networks.
Concept tested: Palo Alto Networks inter-vsys routing and communication
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/virtual-systems/configure-inter-vsys-routing.html
Topics
Community Discussion
No community discussion yet for this question.