Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementHard

A network engineer wants to configure a virtual wire deployment on a Palo Alto Networks firewall. They have two physical interfaces, ethernet1/1 and ethernet1/2, that need to be part of the virtual wire. Which configuration object must be created and applied to these interfaces?

  1. AA Tap interface for passive monitoring.
  2. BA VLAN interface with an associated VLAN ID.
  3. CA Virtual Wire interface with a Virtual Wire object.
  4. DA Layer 3 interface with a static IP address.
Show answer & explanation

Correct answer: C. A Virtual Wire interface with a Virtual Wire object.

For a virtual wire deployment, you must configure the physical interfaces as 'Virtual Wire' type interfaces and then assign them to a 'Virtual Wire' object. This object logically binds the two interfaces together, allowing the firewall to function as a bump-in-the-wire without requiring IP addresses on the interfaces.

Why the other options are wrong

  • A. Tap interfaces are for out-of-band monitoring and do not actively forward or secure traffic inline.
  • B. VLAN interfaces (subinterfaces) are used to carry traffic for specific VLANs on a Layer 3 or Layer 2 interface, but not for the fundamental virtual wire concept itself.
  • D. Layer 3 interfaces are used for routing, not for transparent virtual wire deployments.

Virtual Wire

A deployment mode for Palo Alto Networks firewalls where two interfaces are logically bound to act as a 'bump-in-the-wire', inspecting traffic without requiring IP addresses on those interfaces.

  • Transparently inserts the firewall into a network segment.
  • Requires two physical interfaces.
  • Uses 'Virtual Wire' interface type and 'Virtual Wire' object.

Memory trick: To make your firewall a transparent wire, bind two interfaces with a Virtual Wire's fire!

More Initial Configuration and Management questions