Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium
A network administrator is troubleshooting an issue where users are unable to access internal resources when connected via GlobalProtect. The GlobalProtect client connects successfully, and the user authenticates, but traffic does not pass. The administrator suspects a routing issue. Which command on the Palo Alto Networks firewall would be most helpful to diagnose the routing path for traffic originating from the GlobalProtect tunnel interface?
- Ashow routing route
- Bdebug global-protect-gateway
- Ctest routing-flow
- Dshow interface tunnel.1
Show answer & explanationAnswer & explanation
Correct answer: C. test routing-flow
The 'test routing-flow' command allows the administrator to simulate traffic from a specific source, including a GlobalProtect tunnel interface, to a destination and see the exact routing path the firewall would take, which is ideal for diagnosing routing issues.
Why the other options are wrong
- A. 'show routing route' displays the routing table but doesn't simulate a flow from a specific interface, which is crucial for GlobalProtect routing.
- B. 'debug global-protect-gateway' provides detailed debugging for the gateway process itself, not specifically the routing path for client traffic.
- D. 'show interface tunnel.1' displays the status of the tunnel interface but doesn't provide routing path information for traffic traversing it.
test routing-flow
A Palo Alto Networks CLI command that simulates a packet flow through the firewall's routing engine to determine the egress interface and next-hop.
- Useful for diagnosing routing issues.
- Can specify source/destination IP, port, protocol, and ingress interface.
- Shows the exact routing decision the firewall would make.
Memory trick: Test the flow to know where the packets go.