Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementEasy

A network administrator is performing the initial setup of a new Palo Alto Networks firewall. They need to configure the management interface to use a static IP address, subnet mask, and default gateway. Which of the following is the correct sequence of steps to achieve this using the command-line interface (CLI)?

  1. Aconfigure set deviceconfig system ip-address 192.168.1.1 set deviceconfig system netmask 255.255.255.0 set deviceconfig system default-gateway 192.168.1.254 commit
  2. Bset deviceconfig system ip-address 192.168.1.1 netmask 255.255.255.0 set deviceconfig system default-gateway 192.168.1.254 commit
  3. Cconfigure set deviceconfig system type static ip-address 192.168.1.1 netmask 255.255.255.0 default-gateway 192.168.1.254 commit
  4. Dset deviceconfig system ip-address 192.168.1.1 netmask 255.255.255.0 default-gateway 192.168.1.254 commit
Show answer & explanation

Correct answer: C. configure set deviceconfig system type static ip-address 192.168.1.1 netmask 255.255.255.0 default-gateway 192.168.1.254 commit

The correct CLI syntax for configuring a static IP address, subnet mask, and default gateway for the management interface requires entering configuration mode first, then using a single 'set deviceconfig system' command with 'type static' to define all parameters.

Why the other options are wrong

  • A. Incorrect. While it enters configuration mode, it attempts to set each parameter individually, which is not the correct consolidated syntax for the management interface configuration.
  • B. Incorrect, as 'type static' is missing, and 'default-gateway' is a parameter within the 'set deviceconfig system' command, not a separate command at this level.
  • D. Incorrect syntax; 'type static' is missing, and the default-gateway is typically set separately or within a specific command structure.

CLI Management IP Configuration

Configuring the management interface's IP address, subnet mask, and default gateway using the Palo Alto Networks firewall's command-line interface.

  • Requires entering configuration mode.
  • Uses 'set deviceconfig system' command.
  • Specifies 'type static' for manual IP assignment.

Memory trick: Configuring a static management IP on the CLI is like telling the firewall 'configure yourself, then set your system to static with these network details, and remember to commit it!'

More Initial Configuration and Management questions