A pilot project involves deploying a Palo Alto Networks firewall in an existing data center. The project goal is to gain full visibility into all traffic (Layer 2 through Layer 7) for auditing and compliance purposes, without actively blocking any traffic or altering the current network configuration. Which deployment mode should be chosen?
- ALayer 3
- BTap
- CHA Active/Passive
- DVirtual Wire
Show answer & explanationAnswer & explanation
Correct answer: B. Tap
The key constraints are 'full visibility into all traffic (Layer 2 through Layer 7)', 'without actively blocking any traffic', and 'without altering the current network configuration'. Tap mode is specifically designed for passive monitoring, providing full visibility and logging without impacting traffic flow or requiring network changes. While Virtual Wire provides visibility without IP/routing changes, it *does* actively block traffic based on policies, which contradicts the 'without actively blocking' requirement.
Why the other options are wrong
- A. Layer 3 mode actively routes and blocks, and requires configuration changes.
- C. HA Active/Passive is a redundancy configuration, not a deployment mode for passive monitoring.
- D. Virtual Wire mode actively blocks traffic based on policies, which is disallowed by the 'without actively blocking' constraint.
Tap Mode Use Cases
Tap mode is ideal for passive traffic monitoring, auditing, compliance, and proof-of-concept deployments where full visibility is needed without impacting network operations or actively enforcing security policies.
- Passive monitoring only
- No impact on network flow
- Full L2-L7 visibility
- Excellent for auditing and compliance
Memory trick: Tap mode watches with keen eye, letting all traffic pass by.