PCSFE Exam QuestionsBrowse all questions from this exam

PCSFE Exam - Question 65


After configuring a new software VM-Series firewall, the network team cannot detect any traffic being transmitted or received on the correct VLAN of the network switch. However, they are able to ping the management IP. Which two actions should be taken to troubleshoot this issue? (Choose two.)

Show Answer
Correct Answer: CD

To troubleshoot the issue of the network team not detecting any traffic being transmitted or received on the correct VLAN of the network switch, it's crucial to check the port groups and port mapping on the hypervisor to ensure correct setup and connectivity. Additionally, using the 'show counter global filter' command can help identify if packets are being dropped, which may indicate network or configuration issues, especially considering the implicit 'deny all' policy that new firewalls might have.

Discussion

2 comments
Sign in to comment
ChrjSM0512Options: CD
Jun 2, 2024

I can not see a way of tshoot data plane port through management plane port in this scenario, therefore C and D must be the option...B would be the option after D option is not enough.. tricky question again

1298ac2Options: CD
Jun 27, 2024

Difficult, I think I would go with C,D. With D you can check if packets are dropped. With a new firewall the reason might be the implicit "deny all" policy.