Palo Alto Networks Certified Network Security Administrator (PCNSA)Initial Configuration and ManagementMedium
A network administrator is performing the initial setup of a new Palo Alto Networks firewall. They have configured the management interface and basic network settings. To ensure that the firewall can communicate with external services for updates, WildFire, and DNS, which type of route must be configured on the firewall if it's not directly connected to the internet?
- APolicy-based route
- BDefault route
- CBGP route
- DStatic route
Show answer & explanationAnswer & explanation
Correct answer: B. Default route
A default route (0.0.0.0/0) is essential for the firewall to reach destinations for which it does not have a more specific route in its routing table. This is critical for connecting to external services like update servers, WildFire, and external DNS servers if the firewall's management interface is not directly internet-connected.
Why the other options are wrong
- A. Policy-based routes override normal routing based on criteria like source/destination IP, not for general internet access.
- C. BGP (Border Gateway Protocol) is a dynamic routing protocol for large-scale internet routing, typically not used for initial management access to external services unless in a very specific edge scenario.
- D. Static routes are for specific destinations; a default route is needed for all unknown destinations.
Default Route for Firewall Services
A 0.0.0.0/0 route configured on a Palo Alto Networks firewall to direct traffic for all unknown destinations, essential for reaching external services.
- Acts as a 'last resort' route.
- Critical for firewall updates, WildFire, external DNS, and cloud services.
- Configured under Network > Virtual Routers.
Memory trick: For the firewall to 'find its way' to the internet for updates, it needs a 'default map' (default route).