PCNSE · Question #89
A Network Administrator wants to deploy a Large Scale VPN solution. The Network Administrator has chosen a GlobalProtect Satellite solution. This configuration needs to be deployed to multiple remote
The correct answer is B. Create a Template with the appropriate IPSec tunnel settings. To deploy GlobalProtect Satellite configurations to multiple remote offices using Panorama, the IPSec tunnel settings should be configured within a Template.
Question
A Network Administrator wants to deploy a Large Scale VPN solution. The Network Administrator has chosen a GlobalProtect Satellite solution. This configuration needs to be deployed to multiple remote offices and the Network Administrator decides to use Panorama to deploy the configurations. How should this be accomplished?
Options
- ACreate a Template with the appropriate IKE Gateway settings
- BCreate a Template with the appropriate IPSec tunnel settings
- CCreate a Device Group with the appropriate IKE Gateway settings
- DCreate a Device Group with the appropriate IPSec tunnel settings
How the community answered
(44 responses)- A5% (2)
- B84% (37)
- C2% (1)
- D9% (4)
Why each option
To deploy GlobalProtect Satellite configurations to multiple remote offices using Panorama, the IPSec tunnel settings should be configured within a Template.
While IKE Gateway settings are essential for VPNs, they are components within the broader IPSec tunnel configuration, and selecting the IPSec tunnel settings template is more encompassing for deploying the entire VPN solution.
Panorama Templates are used to define and push configuration settings, including the comprehensive IPSec tunnel settings required for GlobalProtect Satellite, to multiple managed firewalls, ensuring consistent and scalable deployment.
Device Groups in Panorama are primarily used to apply shared policies across multiple firewalls, not to deploy configuration settings such as IKE Gateway settings.
Device Groups are used for policy application, whereas Templates are the correct Panorama objects for deploying interface and VPN tunnel configurations like IPSec tunnel settings.
Concept tested: Panorama template and device group usage for GlobalProtect Satellite
Source: https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/use-templates-to-manage-firewall-configurations
Topics
Community Discussion
No community discussion yet for this question.