Palo Alto Networks Certified Network Security Administrator (PCNSA)Palo Alto Networks Security PlatformEasy

A security architect is designing a network for a new branch office. The design requires the Palo Alto Networks firewall to act as the default gateway for all internal subnets and perform inter-VLAN routing, in addition to security functions. Which firewall deployment mode should be selected for this scenario?

  1. AVirtual Wire
  2. BHA (High Availability)
  3. CLayer 3
  4. DTap
Show answer & explanation

Correct answer: C. Layer 3

Layer 3 deployment mode allows the firewall to participate in routing and act as a default gateway. This is essential for inter-VLAN routing and when the firewall needs to be the central point for network traffic forwarding and security.

Why the other options are wrong

  • A. Virtual Wire mode operates transparently at Layer 2 and does not perform routing functions.
  • B. HA is a configuration for redundancy, not a deployment mode that determines routing capabilities.
  • D. Tap mode passively monitors traffic and does not forward or block it.

Layer 3 Deployment Mode

A firewall deployment where the device functions as a router, forwarding traffic between different IP subnets and acting as a default gateway.

  • Supports routing protocols and NAT.
  • Commonly used as a perimeter firewall.
  • Enables inter-VLAN routing.

Memory trick: Layer 3 is like a traffic cop AND a customs agent, directing and inspecting all traffic.

More Palo Alto Networks Security Platform questions