ExamGecko
Question list
Search
Search

Related questions











Question 187 - PCNSE discussion

Report
Export

What happens when an A/P firewall cluster synchronizes IPsec tunnel security associations (SAs)?

A.
Phase 1 and Phase 2 SAs are synchronized over HA3 links.
Answers
A.
Phase 1 and Phase 2 SAs are synchronized over HA3 links.
B.
Phase 1 SAs are synchronized over HA1 links.
Answers
B.
Phase 1 SAs are synchronized over HA1 links.
C.
Phase 2 SAs are synchronized over HA2 links.
Answers
C.
Phase 2 SAs are synchronized over HA2 links.
D.
Phase 1 and Phase 2 SAs are synchronized over HA2 links.
Answers
D.
Phase 1 and Phase 2 SAs are synchronized over HA2 links.
Suggested answer: C

Explanation:

From the Palo Alto documentation below, "when a VPN is terminated on a Palo Alto firewall HA pair, not all IPSEC related information is synchronized between the firewalls... This is an expected behavior. IKE phase 1 SA information is NOT synchronized between the HA firewalls."And from the second link, "Data link (HA2) is used to sync sessions, forwarding tables, IPSec security associations, and ARP tables between firewalls in the HA pair. Data flow on the HA2 link is always unidirectional (except for the HA2 keep-alive). It flows from the active firewall to the passive firewall."https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAuZCAW&lang=e n_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDe tailhttps://help.aryaka.com/display/public/KNOW/Palo+Alto+Networks+NFV+Technical+Brief

asked 23/09/2024
Maxime ESSIS
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first