Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium
A network engineer is troubleshooting a newly configured Layer 3 subinterface on a Palo Alto Networks firewall. The subinterface has been assigned an IP address, placed in a security zone, and connected to a switch. However, devices connected to the switch cannot use the firewall as their default gateway, and pinging the subinterface IP from the switch fails. The switch port is configured as a trunk port allowing the corresponding VLAN. Which command would be most effective on the Palo Alto Networks firewall to quickly diagnose the issue?
- Adebug dataplane packet-diag show summary
- Bshow routing route
- Cshow interface all
- Dtest security-policy-match source <switch-IP> destination <subinterface-IP>
Show answer & explanationAnswer & explanation
Correct answer: C. show interface all
The 'show interface all' command provides a comprehensive overview of all interfaces, including their operational status, assigned IP addresses, zones, and link status. If devices cannot ping the subinterface IP, it often indicates a fundamental issue with the interface itself, such as being down, incorrect VLAN tag, or misconfiguration. This command would quickly reveal if the subinterface is up/up, has the correct IP, and if its VLAN tag matches the switch configuration.
Why the other options are wrong
- A. While 'debug dataplane packet-diag' is powerful, 'show interface all' is a more direct and less intrusive first step to check the basic health of the interface itself when direct reachability fails.
- B. Routing table issues would affect traffic *forwarded* by the firewall, not direct pingability of its own interface IP.
- D. Security policy match is for traffic *through* the firewall, not for direct reachability of the firewall's own interface IP. The problem states pinging the subinterface fails, indicating a lower-level issue.
L3 Subinterface Troubleshooting
Verifying the operational status and configuration of a Layer 3 subinterface on a Palo Alto Networks firewall is essential for initial connectivity troubleshooting.
- Subinterfaces require VLAN tags.
- Must be up/up to pass traffic.
- IP address and zone assignment are critical.
Memory trick: Subinterface needs 'Status Check' for a Solid Link.