Palo Alto Networks Certified Network Security Administrator (PCNSA)Palo Alto Networks Security PlatformMedium

A network administrator needs to deploy a Palo Alto Networks firewall to protect a segment of their network. The firewall must act as the default gateway for the devices in this segment, terminate VPN tunnels, and perform routing between different subnets. Which deployment mode should the administrator choose?

  1. ATap Mode
  2. BLayer 2 Mode
  3. CVirtual Wire Mode
  4. DLayer 3 Mode
Show answer & explanation

Correct answer: D. Layer 3 Mode

Layer 3 mode allows the firewall to function as a router, acting as a default gateway, terminating VPNs, and performing routing between subnets, which aligns with all the requirements.

Why the other options are wrong

  • A. Tap mode is for passive monitoring and does not participate in active network functions like routing or VPN termination.
  • B. Layer 2 mode acts as a transparent bridge and does not perform Layer 3 routing or act as a default gateway.
  • C. Virtual Wire mode is transparent and does not act as a default gateway or perform routing.

Layer 3 Mode

Layer 3 mode configures a Palo Alto Networks firewall to function as a router, allowing it to act as a default gateway, perform routing between subnets, and terminate VPN tunnels.

  • Firewall acts as a router
  • Interfaces require IP addresses
  • Can be a default gateway for network segments
  • Supports routing protocols and VPN termination

Memory trick: Layer 3: The 'router' layer, directing all traffic.

More Palo Alto Networks Security Platform questions