Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementEasy

A network administrator is performing the initial setup of a new Palo Alto Networks firewall. After connecting to the management port, they attempt to access the web interface but receive a connection refused error. Which of the following is the MOST likely cause for this issue if no other configuration has been performed?

  1. AThe administrator's workstation is on a different subnet than the firewall's default management IP.
  2. BThe firewall's management interface is configured for DHCP, but no DHCP server is available.
  3. CThe administrative access type (HTTP/HTTPS) is not enabled on the management interface.
  4. DThe firewall's default factory configuration requires a console cable for initial web interface enablement.
Show answer & explanation

Correct answer: A. The administrator's workstation is on a different subnet than the firewall's default management IP.

By default, Palo Alto Networks firewalls have a static management IP address (192.168.1.1/24). If the administrator's workstation is not on the same subnet, they will not be able to reach the firewall's web interface.

Why the other options are wrong

  • B. The management interface defaults to a static IP, not DHCP, so this is incorrect.
  • C. HTTPS is enabled by default on the management interface for initial access, so this is incorrect.
  • D. While console access is an option, it's not strictly required to enable the web interface, as HTTPS is enabled by default. The issue is more likely network connectivity.

Default Management IP

Palo Alto Networks firewalls come with a pre-configured static IP address on their management interface for initial setup.

  • Default IP is 192.168.1.1/24.
  • HTTPS is enabled by default for web UI access.
  • Requires connecting to the MGT port.

Memory trick: Connect to the fiery heart, but check your network part!

More Initial Configuration and Management questions