Palo Alto Networks Certified Network Security Administrator (PCNSA)Palo Alto Networks Security PlatformHard

A security engineer is integrating a Palo Alto Networks firewall into an existing network where the firewall needs to perform Layer 2 switching functions for several VLANs while also applying security policies between them. The firewall should not participate in Layer 3 routing for these segments but must enforce security. Which deployment mode should be chosen?

  1. AVirtual Wire Mode
  2. BLayer 3 Mode
  3. CLayer 2 Mode
  4. DTap Mode
Show answer & explanation

Correct answer: C. Layer 2 Mode

Layer 2 mode allows the Palo Alto Networks firewall to function as a transparent Layer 2 switch. It can participate in VLANs and enforce security policies between them, while forwarding traffic based on MAC addresses, without performing Layer 3 routing. This is suitable when the firewall needs to segment and secure a Layer 2 domain.

Why the other options are wrong

  • A. Virtual Wire mode connects two segments transparently without switching or routing across multiple VLANs in a traditional sense.
  • B. Layer 3 mode performs routing and acts as a default gateway, which is explicitly not desired.
  • D. Tap mode is for passive monitoring only and does not enforce security policies or forward traffic inline.

Layer 2 Deployment Mode

A firewall deployment mode where the Palo Alto Networks firewall acts as a transparent Layer 2 switch, forwarding traffic based on MAC addresses and enforcing security policies between connected Layer 2 segments or VLANs.

  • No Layer 3 routing is performed by the firewall.
  • Supports VLANs and subinterfaces.
  • Ideal for segmenting a flat network with security.

Memory trick: Layer 2 mode is like a smart security bridge, inspecting traffic without being a router.

More Palo Alto Networks Security Platform questions