nerdexam
Palo_Alto_Networks

PCSFE · Question #5

How must a Palo Alto Networks Next-Generation Firewall (NGFW) be configured in order to secure traffic in a Cisco ACI environment?

The correct answer is B. It must use a Layer 3 underlay network.. A Palo Alto Networks Next-Generation Firewall (NGFW) must be configured to use a Layer 3 underlay network in order to secure traffic in a Cisco ACI environment. A Layer 3 underlay network is a physical network that provides IP connectivity between devices, such as routers, switch

Deployment and Configuration

Question

How must a Palo Alto Networks Next-Generation Firewall (NGFW) be configured in order to secure traffic in a Cisco ACI environment?

Options

  • AIt must be deployed as a member of a device cluster.
  • BIt must use a Layer 3 underlay network.
  • CIt must receive all forwarding lookups from the network controller.
  • DIt must be identified as a default gateway.

How the community answered

(30 responses)
  • A
    10% (3)
  • B
    80% (24)
  • C
    3% (1)
  • D
    7% (2)

Explanation

A Palo Alto Networks Next-Generation Firewall (NGFW) must be configured to use a Layer 3 underlay network in order to secure traffic in a Cisco ACI environment. A Layer 3 underlay network is a physical network that provides IP connectivity between devices, such as routers, switches, and firewalls. A Palo Alto Networks NGFW must use a Layer 3 underlay network to communicate with the Cisco ACI fabric and receive traffic redirection from the Cisco ACI policy- based redirect mechanism. A Palo Alto Networks NGFW does not need to be deployed as a member of a device cluster, receive all forwarding lookups from the network controller, or be identified as a default gateway in order to secure traffic in a Cisco ACI environment, as those are not valid requirements or options for firewall integration with Cisco ACI.

Topics

#NGFW#Cisco ACI#Layer 3 underlay#network configuration

Community Discussion

No community discussion yet for this question.

Full PCSFE Practice