NGFW-Engineer: Palo Alto Networks Next-Generation Firewall Engineer Tunnel Practice Questions
The free NGFW-Engineer: Palo Alto Networks Next-Generation Firewall Engineer questions that deal with tunnel, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #2
After an engineer configures an IPSec tunnel with a Cisco ASA, the Palo Alto Networks firewall generates system messages reporting the tunnel is failing to establish. Which of the following actions will resolve this issue?
Correct answer: B
Explanation
The Proxy IDs (or Traffic Selectors) define the local and remote subnets that are allowed to communicate over the IPSec tunnel. If the Proxy IDs on the Palo Alto Networks firewall do not match the configuration on the Cisco ASA, the tunnel will fail to establish because the firewalls won't agree on which traffic to encrypt. Ensuring that the Proxy IDs match between the Palo Alto Networks firewall and the Cisco ASA will resolve the issue.
Question #9
Which two statements apply to configuring required security rules when setting up an IPSec tunnel between a Palo Alto Networks firewall and a third-party gateway? (Choose two.)
Select 2 answers.
Correct answer: C, D
Explanation
Separate rules must be created for each direction: Palo Alto Networks firewalls enforce security policies based on traffic direction. To allow bidirectional communication through the IPSec tunnel, two separate rules are required - one for incoming and one for outgoing traffic. IKE negotiation and IPSec/ESP packets are denied by default: Palo Alto Networks firewalls use an interzone default deny policy, meaning that unless an explicit policy allows IKE (UDP 500/4500) and ESP (protocol 50) traffic, the firewall will block these packets, preventing tunnel establishment. Therefore, administrators must create explicit rules permitting IKE and IPSec/ESP traffic to the firewall's external interface.
Continue with NGFW-Engineer: Palo Alto Networks Next-Generation Firewall Engineer
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in NGFW-Engineer: Palo Alto Networks Next-Generation Firewall Engineer, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
All NGFW-Engineer: Palo Alto Networks Next-Generation Firewall Engineer practice questions →
