Palo Alto Networks Certified Network Security Engineer (PCNSE)Deploy and ConfigureHard
A company is migrating its network infrastructure to a new data center and requires a seamless transition for its critical applications. During this migration, they need to implement a security solution that can inspect traffic without requiring any changes to the existing network topology (IP addresses, routing). Which Palo Alto Networks interface configuration would best meet this requirement for transparent inspection?
- ALayer 3 interface with a virtual router
- BVirtual Wire (L2 transparent mode)
- CTap interface for out-of-band monitoring
- DLayer 2 interface with a VLAN subinterface
Show answer & explanationAnswer & explanation
Correct answer: B. Virtual Wire (L2 transparent mode)
A Virtual Wire (L2 transparent mode) configuration allows the Palo Alto Networks firewall to be inserted directly into a network segment between two devices (like a switch and a router) without requiring any changes to IP addressing or routing, functioning transparently.
Why the other options are wrong
- A. Layer 3 interfaces require IP addresses and participate in routing, which would necessitate changes to the existing network topology.
- C. Tap interfaces are for passive monitoring only and do not actively inspect or enforce policies on traffic, thus not providing a 'security solution' in line.
- D. Layer 2 interfaces are used for switching and would still require VLAN configuration and potentially changes to existing switch configurations.
Virtual Wire Interface
A Palo Alto Networks firewall interface type that operates in a transparent Layer 2 mode, allowing the firewall to be inserted into a network segment without requiring changes to the existing network topology.
- Acts as a 'bump-in-the-wire'.
- Does not have an IP address on the data plane.
- Forwards traffic based on MAC addresses.
- Enforces security policies transparently.
Memory trick: Virtual Wire's the ghost, for transparent protection the most!