Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureMedium

A network architect is designing a new branch office deployment that requires a secure, encrypted tunnel back to the corporate headquarters. Both sites use Palo Alto Networks firewalls. The branch office has a dynamic public IP address. Which type of site-to-site VPN configuration is best suited for this scenario?

  1. APolicy-based VPN
  2. BRoute-based VPN with static VTI
  3. CRoute-based VPN with a dynamic peer
  4. DSSL VPN
Show answer & explanation

Correct answer: C. Route-based VPN with a dynamic peer

When one side of a site-to-site VPN has a dynamic public IP address, a route-based VPN configured with a dynamic peer (using a dynamic DNS hostname or a pre-shared key with 'any' peer ID) is the most appropriate solution. This allows the VPN tunnel to re-establish even if the branch office's public IP changes.

Why the other options are wrong

  • A. Policy-based VPNs are older and less flexible, and typically require static IPs for both endpoints.
  • B. A static VTI (Virtual Tunnel Interface) requires both endpoints to have static IP addresses.
  • D. SSL VPN is primarily for remote access (client-to-site) and not typically used for site-to-site tunnels between firewalls.

Dynamic Peer VPN

A dynamic peer VPN configuration allows one or both VPN endpoints to have a dynamic public IP address, typically using a FQDN or a 'any' peer ID for identification.

  • Essential for branch offices with dynamic IPs.
  • Often uses a Dynamic DNS service to update the FQDN.
  • Requires specific IKE Gateway configuration for dynamic peers.

Memory trick: VPNs Connect Sites: Route for Dynamic, Policy for Static.

More Deploy and Configure questions