ExamGecko
Question list
Search
Search

Related questions











Question 374 - PCNSE discussion

Report
Export

A network security engineer needs to ensure that virtual systems can communicate with one another within a Palo Alto Networks firewall. Separate virtual routers (VRs) are created for each virtual system.

In addition to confirming security policies, which three configuration details should the engineer focus on to ensure communication between virtual systems? {Choose three.)

A.
External zones with the virtual systems added.
Answers
A.
External zones with the virtual systems added.
B.
Layer 3 zones for the virtual systems that need to communicate.
Answers
B.
Layer 3 zones for the virtual systems that need to communicate.
C.
Add a route with next hop set to none, and use the interface of the virtual systems that need to communicate.
Answers
C.
Add a route with next hop set to none, and use the interface of the virtual systems that need to communicate.
D.
Add a route with next hop next-vr by using the VR configured in the virtual system.
Answers
D.
Add a route with next hop next-vr by using the VR configured in the virtual system.
E.
Ensure the virtual systems are visible to one another.
Answers
E.
Ensure the virtual systems are visible to one another.
Suggested answer: A, D, E

Explanation:

For virtual systems (vSys) on a Palo Alto Networks firewall to communicate with each other, especially when separate virtual routers (VRs) are used for each vSys, the configuration must facilitate proper routing and security policy enforcement. The key aspects to focus on include:

A) External zones with the virtual systems added:

External zones are special types of zones that are used to facilitate traffic flow between virtual systems within the same physical firewall. By adding virtual systems to an external zone, you enable them to communicate with each other, effectively bypassing the need for traffic to exit and re-enter the firewall.

D) Add a route with next hop next-vr by using the VR configured in the virtual system:

When using separate VRs for each vSys, it's essential to configure inter-VR routing. This is done by adding routes in each VR with the next hop set to 'next-vr', specifying the VR of the destination vSys. This setup enables traffic to be routed from one virtual system's VR to another, facilitating communication between them.

E) Ensure the virtual systems are visible to one another:

Visibility between virtual systems is a prerequisite for inter-vSys communication. This involves configuring the virtual systems in a way that they are aware of each other's existence. This is typically managed in the vSys settings, where you can specify which virtual systems can communicate with each other.

By focusing on these configuration details, the network security engineer can ensure that the virtual systems can communicate effectively, maintaining the necessary isolation while allowing the required traffic flow.

asked 23/09/2024
Jeffrey Tiffany
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first