Exam PCNSE All QuestionsBrowse all questions from this exam
Question 549

Based on the screenshots above, what is the correct order in which the various rules are deployed to firewalls inside the DATACENTER_DG device group?

    Correct Answer: D

    The correct order in which the various rules are deployed to firewalls inside the DATACENTER_DG device group is as follows: shared pre-rules, DATACENTER_DG pre-rules, rules configured locally on the firewall, DATACENTER_DG post-rules, shared post-rules, and finally DATACENTER_DG default rules. The shared default rules are typically applied last, but since the question involves the DATACENTER_DG device group having overrides, the specific ordering for that context should be considered.

Discussion
news088Option: D

Would choose D. base on doc from dgonz the order is: Shared pre rules DG prer ules local rules DG post rules Shared post rules default rules Then be aware of order in DG when 2 config matches. in DG the config maintained is the child. On template is the oposite , the config maintained is the father. From the same doc. If you override default rules, their order of precedence runs from the lowest context to the highest: overridden settings at the firewall level take precedence over settings at the device group level, which take precedence over settings at the Shared level.

MtroOption: D

Shared Pre-Policies Device group hierarchy Pre-Policies Local Firewall Policies Device group hierarchy Post-Policies Shared Post-Policies Default Rules there is no shared defaukt event hough it exist and it can be used as well. This is a document from Palo training ... we have to use same wording as they provide it ( it is an exam so go with whatever they want the answer to be. Even if it's not 100% correct)

PachecoOption: A

Default rules belong to the Shared level and not any particular device group, which leaves us with only option A and C. The following doc states this and also explicitly gives us the order :) Shared pre Group pre Locals Group post Shared post Shared defaults https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies

MarshpillowzOption: A

I think A

TeachTrooperOption: D

I would choose D based on https://docs.paloaltonetworks.com/panorama/11-0/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies: If you override default rules, their order of precedence runs from the lowest context to the highest: overridden settings at the firewall level take precedence over settings at the device group level, which take precedence over settings at the Shared level. As we have overridden the default ruleset in the device group it will be applied instead of the shared one.

Jared28

TeachTrooper is correct. However, the answer should also include shared default rule at the very bottom as the interzone rule does not have an override. Due to so many people stating A, I labbed it, re-confirming it, to make sure I wasn't thinking of this incorrectly.

hifumi_daisukiOption: A

Shared Pre-Rules Device Group Pre-Rules Local Firewall Rules Device Group Post Rule Shared Post-Rules Default Rules The default rules apply only to the Security rulebase, and are predefined on Panorama (at the Shared level) and the firewall (in each vsys). https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies

wallakaOption: A

A. This one isn't as tricky as it looks--device groups don't have default rules.

Eiffelsturm

sure they have. Take a look into your Panorama

tune_inOption: A

https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies DG post-rules before Shared post rules

dgonzOption: D

yup.. sorry it is D

lmla89Option: D

As per News088

dgonzOption: A

https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies

homersimpson

Why do you keep voting different answers?

apiloranOption: D

Screenshots indicate that the default rules have been overridden. The accurate answer is D. If you override default rules, their order of precedence runs from the lowest context to the highest: overridden settings at the firewall level take precedence over settings at the device group level, which take precedence over settings at the Shared level.

moobeOption: A

Based on that A 1. Shared pre-rules 2. Device group pre-rules 3. Local firewall rules 4. Device group post-rules 5. Shared post-rules 6. intrazone-default interzone-default https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/panorama-overview/centralized-firewall-configuration-and-update-management/device-groups/device-group-policies

scanossa

I got this question in the exam