Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootHard

A technician is troubleshooting a network connectivity issue on a Palo Alto Networks firewall. After making a configuration change, a specific internal host can no longer reach an external server. The technician suspects a routing issue. Which CLI command would the technician use to verify the effective routing path for traffic originating from the internal host's IP address to the external server's IP address, including any policy-based forwarding or NAT effects?

  1. Atest routing fib-lookup ip <destination_ip> virtual-router <vr_name>
  2. Btest packet-diag stage all start source <src_ip> destination <dst_ip> protocol <protocol> sport <src_port> dport <dst_port>
  3. Cshow routing route
  4. Dtest routing pbf-lookup from <source_ip> to <destination_ip> protocol <protocol> port <port>
Show answer & explanation

Correct answer: B. test packet-diag stage all start source <src_ip> destination <dst_ip> protocol <protocol> sport <src_port> dport <dst_port>

The 'test packet-diag stage all start' command provides the most comprehensive view of how a packet traverses the firewall, including all stages of processing: ingress, routing (including PBF), NAT, security policy, and egress. This allows the technician to see the effective routing path after all policy and NAT considerations, which is crucial for complex routing issues.

Why the other options are wrong

  • A. This command only shows the FIB (Forwarding Information Base) lookup based on the destination IP within a specific virtual router, without considering source IP, PBF, or NAT.
  • C. This command shows the static/dynamic routing table but doesn't account for policy-based forwarding (PBF) or NAT effects on routing.
  • D. This command specifically tests PBF rules but doesn't show the full routing path or other firewall processing stages like NAT or security policy after PBF.

Test Packet Diagnostic Tool

The 'test packet-diag' CLI command on Palo Alto Networks firewalls simulates a packet's traversal through the device, detailing each processing stage (routing, NAT, policy, etc.) to comprehensively troubleshoot traffic flow.

  • Simulates a packet from ingress to egress.
  • Shows routing decisions including PBF.
  • Displays NAT translations and security policy matches.

Memory trick: To trace the packet's whole journey, you need a full travel itinerary!

More Troubleshoot questions