Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementHard
A network engineer is configuring a new Palo Alto Networks firewall and needs to enable IPv6 connectivity on a Layer 3 interface. After assigning an IPv6 address, the engineer attempts to ping an IPv6 host on a different subnet but fails. All security policies are temporarily set to 'allow any'. What is a common missing configuration for IPv6 routing on Layer 3 interfaces that might cause this issue?
- AConfiguring a virtual wire for IPv6 traffic.
- BDisabling IPv4 on the interface to prioritize IPv6.
- CAdding the Layer 3 interface to a virtual router.
- DEnabling DHCPv6 client on the interface.
Show answer & explanationAnswer & explanation
Correct answer: C. Adding the Layer 3 interface to a virtual router.
For any Layer 3 interface (IPv4 or IPv6) to participate in routing, it must be assigned to a virtual router. Even with an IPv6 address, if the interface is not part of a virtual router, the firewall does not know how to forward traffic from or to that subnet, leading to connectivity issues to different subnets.
Why the other options are wrong
- A. Virtual wire interfaces are Layer 2 and do not perform Layer 3 routing.
- B. Disabling IPv4 is unnecessary and unrelated to enabling IPv6 routing; both can coexist on the same interface.
- D. DHCPv6 client is for dynamic address assignment, not for enabling routing functionality.
IPv6 Layer 3 Routing Prerequisite
For a Palo Alto Networks firewall's Layer 3 interface with an IPv6 address to route traffic, it must be assigned to a virtual router.
- Applies to both IPv4 and IPv6 on Layer 3 interfaces.
- Virtual Router makes routing decisions.
- Without it, interface is 'isolated' from routing table.
Memory trick: An IPv6 interface without a Virtual Router is a road with no map.