Palo Alto Networks Certified Network Security Administrator (PCNSA)Palo Alto Networks Security PlatformHard
A security engineer is integrating a Palo Alto Networks firewall into an existing network where the firewall needs to perform Layer 2 switching functions for several VLANs while also applying security policies between them. The firewall should not participate in Layer 3 routing for these segments but must enforce security. Which deployment mode should be chosen?
- AVirtual Wire Mode
- BLayer 3 Mode
- CLayer 2 Mode
- DTap Mode
Show answer & explanationAnswer & explanation
Correct answer: C. Layer 2 Mode
Layer 2 mode allows the Palo Alto Networks firewall to function as a transparent Layer 2 switch. It can participate in VLANs and enforce security policies between them, while forwarding traffic based on MAC addresses, without performing Layer 3 routing. This is suitable when the firewall needs to segment and secure a Layer 2 domain.
Why the other options are wrong
- A. Virtual Wire mode connects two segments transparently without switching or routing across multiple VLANs in a traditional sense.
- B. Layer 3 mode performs routing and acts as a default gateway, which is explicitly not desired.
- D. Tap mode is for passive monitoring only and does not enforce security policies or forward traffic inline.
Layer 2 Deployment Mode
A firewall deployment mode where the Palo Alto Networks firewall acts as a transparent Layer 2 switch, forwarding traffic based on MAC addresses and enforcing security policies between connected Layer 2 segments or VLANs.
- No Layer 3 routing is performed by the firewall.
- Supports VLANs and subinterfaces.
- Ideal for segmenting a flat network with security.
Memory trick: Layer 2 mode is like a smart security bridge, inspecting traffic without being a router.