ExamGecko
Question list
Search
Search

Related questions











Question 118 - PCNSE discussion

Report
Export

An engineer needs to permit XML API access to a firewall for automation on a network segment that is routed through a Layer 3 subinterface on a Palo Alto Networks firewall. However, this network segment cannot access the dedicated management interface due to the Security policy.

Without changing the existing access to the management interface, how can the engineer fulfill this request?

A.
Specify the subinterface as a management interface in Setup > Device > Interfaces.
Answers
A.
Specify the subinterface as a management interface in Setup > Device > Interfaces.
B.
Enable HTTPS in an Interface Management profile on the subinterface.
Answers
B.
Enable HTTPS in an Interface Management profile on the subinterface.
C.
Add the network segment's IP range to the Permitted IP Addresses list
Answers
C.
Add the network segment's IP range to the Permitted IP Addresses list
D.
Configure a service route for HTTP to use the subinterface
Answers
D.
Configure a service route for HTTP to use the subinterface
Suggested answer: B

Explanation:

An interface management profile defines which services are available on an interface, such as HTTPS, SSH, ping, or SNMP. By enabling HTTPS in an interface management profile on the subinterface, the engineer can allow XML API access to the firewall for automation on the network segment that is routed through the subinterface. Specifying the subinterface as a management interface in Setup > Device > Interfaces is not possible, as only physical interfaces can be designated as management interfaces. Adding the network segment's IP range to the Permitted IP Addresses list will not help, as this list only applies to the dedicated management interface. Configuring a service route for HTTP to use the subinterface will not help, as this will only affect the outbound traffic from the firewall to external services, not the inbound traffic to the firewall for XML API access. Reference: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/ networking/configure- interfaces/configure-interface-management-profiles https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-panorama-api/get-started-with-the-pan-os-xml-api/enable-api-access

asked 23/09/2024
Miroslav Burzinskij
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first