ExamGecko
Question list
Search
Search

Question 295 - PCNSA discussion

Report
Export

How are service routes used in PAN-OS?

A.
By the OSPF protocol, as part of Dijkstra's algorithm, to give access to the various services offered in the network
Answers
A.
By the OSPF protocol, as part of Dijkstra's algorithm, to give access to the various services offered in the network
B.
To statically route subnets so they are joinable from, and have access to, the Palo Alto Networks external services
Answers
B.
To statically route subnets so they are joinable from, and have access to, the Palo Alto Networks external services
C.
For routing, because they are the shortest path selected by the BGP routing protocol
Answers
C.
For routing, because they are the shortest path selected by the BGP routing protocol
D.
To route management plane services through data interfaces rather than the management interface
Answers
D.
To route management plane services through data interfaces rather than the management interface
Suggested answer: D

Explanation:

Service routes are a feature of PAN-OS that allows the administrator to customize the interface that the firewall uses to send requests to external services, such as DNS, email, Palo Alto Networks updates, User-ID agent, syslog, Panorama, dynamic updates, URL updates, licenses, and AutoFocus1.

By default, the firewall uses the management interface for all service routes, unless the packet destination IP address matches the configured destination service route, in which case the source IP address is set to the source address configured for the destination1.

However, in some scenarios, the administrator may want to use a different interface for service routes, such as when the management interface does not have public internet access, or when the administrator wants to isolate or monitor the traffic for certain services23.

To configure service routes, the administrator can select Device > Setup > Services > Service Route Configuration and customize each service with a source interface and a source address.The administrator can also configure destination service routes to specify a destination IP address and a gateway for each service1.

Service routes are not related to routing protocols such as OSPF or BGP, which are used to exchange routing information between routers and determine the best path to reach a network destination. Service routes are only used to change the interface that the firewall uses to communicate with external services.

Therefore, service routes are used to route management plane services through data interfaces rather than the management interface.

References:

1:Configure Service Routes - Palo Alto Networks2:Setting a Service Route for Services to Use a Dataplane's Interface - Palo Alto Networks3:How to Perform Updates when Management Interface does not have Public Internet Access - Palo Alto Networks


asked 23/09/2024
Marcos Davila
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first