Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementHard

A network engineer is configuring a new Palo Alto Networks firewall and needs to enable IPv6 connectivity on a Layer 3 interface. After assigning an IPv6 address, the engineer attempts to ping an IPv6 host on a different subnet but fails. All security policies are temporarily set to 'allow any'. What is a common missing configuration for IPv6 routing on Layer 3 interfaces that might cause this issue?

  1. AConfiguring a virtual wire for IPv6 traffic.
  2. BDisabling IPv4 on the interface to prioritize IPv6.
  3. CAdding the Layer 3 interface to a virtual router.
  4. DEnabling DHCPv6 client on the interface.
Show answer & explanation

Correct answer: C. Adding the Layer 3 interface to a virtual router.

For any Layer 3 interface (IPv4 or IPv6) to participate in routing, it must be assigned to a virtual router. Even with an IPv6 address, if the interface is not part of a virtual router, the firewall does not know how to forward traffic from or to that subnet, leading to connectivity issues to different subnets.

Why the other options are wrong

  • A. Virtual wire interfaces are Layer 2 and do not perform Layer 3 routing.
  • B. Disabling IPv4 is unnecessary and unrelated to enabling IPv6 routing; both can coexist on the same interface.
  • D. DHCPv6 client is for dynamic address assignment, not for enabling routing functionality.

IPv6 Layer 3 Routing Prerequisite

For a Palo Alto Networks firewall's Layer 3 interface with an IPv6 address to route traffic, it must be assigned to a virtual router.

  • Applies to both IPv4 and IPv6 on Layer 3 interfaces.
  • Virtual Router makes routing decisions.
  • Without it, interface is 'isolated' from routing table.

Memory trick: An IPv6 interface without a Virtual Router is a road with no map.

More Initial Configuration and Management questions