ExamGecko
Question list
Search
Search

Related questions











Question 216 - PCNSE discussion

Report
Export

An administrator has two pairs of firewalls within the same subnet. Both pairs of firewalls have been configured to use High Availability mode with Active/Passive. The ARP tables for upstream routes display the same MAC address being shared for some of these firewalls.

What can be configured on one pair of firewalls to modify the MAC addresses so they are no longer in conflict?

A.
Configure a floating IP between the firewall pairs.
Answers
A.
Configure a floating IP between the firewall pairs.
B.
Change the Group IDs in the High Availability settings to be different from the other firewall pair on the same subnet.
Answers
B.
Change the Group IDs in the High Availability settings to be different from the other firewall pair on the same subnet.
C.
Change the interface type on the interfaces that have conflicting MAC addresses from L3 to VLAN.
Answers
C.
Change the interface type on the interfaces that have conflicting MAC addresses from L3 to VLAN.
D.
On one pair of firewalls, run the CLI command: set network interface vlan arp.
Answers
D.
On one pair of firewalls, run the CLI command: set network interface vlan arp.
Suggested answer: B

Explanation:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm1OCASchange the Group IDs in the High Availability settings to be different from the other firewall pair on the same subnet. This will prevent the MAC addresses from conflicting and allow the firewalls to properly route traffic. You can also configure a floating IP between the firewall pairs if necessary.

asked 23/09/2024
Mark Wingate
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first