Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A network engineer is troubleshooting a newly configured Layer 3 subinterface on a Palo Alto Networks firewall. The subinterface has been assigned an IP address, placed in a security zone, and connected to a switch. However, devices connected to the switch cannot use the firewall as their default gateway, and pinging the subinterface IP from the switch fails. The switch port is configured as a trunk port allowing the corresponding VLAN. Which command would be most effective on the Palo Alto Networks firewall to quickly diagnose the issue?

  1. Adebug dataplane packet-diag show summary
  2. Bshow routing route
  3. Cshow interface all
  4. Dtest security-policy-match source <switch-IP> destination <subinterface-IP>
Show answer & explanation

Correct answer: C. show interface all

The 'show interface all' command provides a comprehensive overview of all interfaces, including their operational status, assigned IP addresses, zones, and link status. If devices cannot ping the subinterface IP, it often indicates a fundamental issue with the interface itself, such as being down, incorrect VLAN tag, or misconfiguration. This command would quickly reveal if the subinterface is up/up, has the correct IP, and if its VLAN tag matches the switch configuration.

Why the other options are wrong

  • A. While 'debug dataplane packet-diag' is powerful, 'show interface all' is a more direct and less intrusive first step to check the basic health of the interface itself when direct reachability fails.
  • B. Routing table issues would affect traffic *forwarded* by the firewall, not direct pingability of its own interface IP.
  • D. Security policy match is for traffic *through* the firewall, not for direct reachability of the firewall's own interface IP. The problem states pinging the subinterface fails, indicating a lower-level issue.

L3 Subinterface Troubleshooting

Verifying the operational status and configuration of a Layer 3 subinterface on a Palo Alto Networks firewall is essential for initial connectivity troubleshooting.

  • Subinterfaces require VLAN tags.
  • Must be up/up to pass traffic.
  • IP address and zone assignment are critical.

Memory trick: Subinterface needs 'Status Check' for a Solid Link.

More Troubleshoot questions