Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementHard
A network engineer wants to configure a virtual wire deployment on a Palo Alto Networks firewall. They have two physical interfaces, ethernet1/1 and ethernet1/2, that need to be part of the virtual wire. Which configuration object must be created and applied to these interfaces?
- AA Tap interface for passive monitoring.
- BA VLAN interface with an associated VLAN ID.
- CA Virtual Wire interface with a Virtual Wire object.
- DA Layer 3 interface with a static IP address.
Show answer & explanationAnswer & explanation
Correct answer: C. A Virtual Wire interface with a Virtual Wire object.
For a virtual wire deployment, you must configure the physical interfaces as 'Virtual Wire' type interfaces and then assign them to a 'Virtual Wire' object. This object logically binds the two interfaces together, allowing the firewall to function as a bump-in-the-wire without requiring IP addresses on the interfaces.
Why the other options are wrong
- A. Tap interfaces are for out-of-band monitoring and do not actively forward or secure traffic inline.
- B. VLAN interfaces (subinterfaces) are used to carry traffic for specific VLANs on a Layer 3 or Layer 2 interface, but not for the fundamental virtual wire concept itself.
- D. Layer 3 interfaces are used for routing, not for transparent virtual wire deployments.
Virtual Wire
A deployment mode for Palo Alto Networks firewalls where two interfaces are logically bound to act as a 'bump-in-the-wire', inspecting traffic without requiring IP addresses on those interfaces.
- Transparently inserts the firewall into a network segment.
- Requires two physical interfaces.
- Uses 'Virtual Wire' interface type and 'Virtual Wire' object.
Memory trick: To make your firewall a transparent wire, bind two interfaces with a Virtual Wire's fire!