PSE-STRATA · Question #158
Which two features can be enabled to support asymmetric routing with redundancy on a Palo Alto networks next-generation firewall (NGFW)? (Choose two.)
The correct answer is A. Active / active high availability (HA) C. non-SYN first packet. Active/Active high availability (A) enables both firewall peers to simultaneously process traffic, and when one peer receives return traffic for a session that was established on the other peer, it forwards that traffic to the session owner - this is the core mechanism that…
Question
Which two features can be enabled to support asymmetric routing with redundancy on a Palo Alto networks next-generation firewall (NGFW)? (Choose two.)
Options
- AActive / active high availability (HA)
- BMultiple virtual systems
- Cnon-SYN first packet
- DAsymmetric routing profile
How the community answered
(21 responses)- A81% (17)
- B14% (3)
- D5% (1)
Explanation
Active/Active high availability (A) enables both firewall peers to simultaneously process traffic, and when one peer receives return traffic for a session that was established on the other peer, it forwards that traffic to the session owner - this is the core mechanism that provides both redundancy and asymmetric routing support. Non-SYN first packet (C) allows the firewall to create a session even when the first packet it sees is not a TCP SYN, which is necessary when asymmetric routing causes the return traffic to arrive at a firewall that never saw the original handshake.
Multiple virtual systems (B) is wrong because vsys is a multi-tenancy feature that partitions one physical firewall into logical instances - it does not address traffic flowing across different physical paths. Asymmetric routing profile (D) is a fabricated distractor; no such named feature exists on Palo Alto NGFWs, and it is designed to sound plausible to candidates unfamiliar with the actual feature set.
Memory tip: Pair "Active/Active" with "non-SYN" as your asymmetric routing duo - Active/Active handles the redundancy side by letting peers share session ownership, and non-SYN handles the packet side by letting a firewall accept traffic mid-stream when it missed the original handshake.
Topics
Community Discussion
No community discussion yet for this question.