Exam PCNSE All QuestionsBrowse all questions from this exam
Question 318

An engineer wants to implement the Palo Alto Networks firewall in VWire mode on the internet gateway and wants to be sure of the functions that are supported on the vwire interface.

What are three supported functions on the VWire interface? (Choose three.)

    Correct Answer: C, D, E

    The Palo Alto Networks virtual wire (VWire) interface supports SSL Decryption, QoS, and NAT functions. You wouldn't use a virtual wire for IPSec because it does not support protocols that require Layer 2 or Layer 3 addresses. Similarly, OSPF, being a routing protocol, is also not supported since VWire interfaces do not participate in routing functions.

Discussion
nose999Options: CDE

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces

al12345Options: CDE

The virtual wire supports blocking or allowing traffic based on virtual LAN (VLAN) tags, in addition to supporting security policy rules, App-ID, Content-ID, User-ID, decryption, LLDP, active/passive and active/active HA, QoS, zone protection (with some exceptions), non-IP protocol protection, DoS protection, packet buffer protection, tunnel content inspection, and NAT. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/virtual-wire-interfaces

TAKUM1yOptions: CDE

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/virtual-wire-interfaces "The virtual wire supports blocking or allowing traffic based on virtual LAN (VLAN) tags, in addition to supporting security policy rules, App-ID, Content-ID, User-ID, decryption, LLDP, active/passive and active/active HA, QoS, zone protection (with some exceptions), non-IP protocol protection, DoS protection, packet buffer protection, tunnel content inspection, and NAT."

ali_sh85Options: CDE

The virtual wire supports the blocking or allowing of traffic based on the virtual LAN (VLAN) tags. The virtual wire also supports Security policy rules, App-ID, Content-ID, User-ID, decryption, LLDP, active/passive and active/active high availability (HA), QoS, zone protection (with some exceptions), non-IP protocol protection, denial of service (DoS) protection, packet buffer protection, tunnel content inspection,and NAT.

123XYZTOptions: CDE

CDE A is incorrect because: You wouldn’t use a virtual wire deployment for interfaces that need to support switching, VPN tunnels, or routing because they require a Layer 2 or Layer 3 address.

JRKhanOptions: CDE

CDE is correct. Vwire interfaces cannot be used as IPsec termination points.

MetgatzOptions: CDE

CDE are the correcto options

XuziOptions: CDE

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces

NawdaOptions: CDE

no switching or routing for Vwire

dgonzOptions: CDE

CDE are correct

sujssOptions: CDE

I guess easiest approach for this is discard anything that needs an IP (or MAC) as Vwire interfaces do not support IP or MAC

GohanF2Options: CDE

It is CDE.

DenskyDenOptions: CDE

CDE. The virtual wire supports blocking or allowing traffic based on virtual LAN (VLAN) tags, in addition to supporting security policy rules, App-ID, Content-ID, User-ID, "DECRYPTION", LLDP, active/passive and active/active HA, "QOS", zone protection (with some exceptions), non-IP protocol protection, DoS protection, packet buffer protection, tunnel content inspection, and "NAT".

aatechlerOptions: CDE

You wouldn’t use a virtual wire deployment for interfaces that need to support switching, VPN tunnels, or routing because they require a Layer 2 or Layer 3 address. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/virtual-wire-interfaces

awtsuritacunaOptions: BDE

Options: B/D/E - The virtual wire allows the firewall to maintain a transparent presence acting as a pass-through link, while still providing security, NAT, and QoS services. - In order for routing (Layer 3) control packets to pass through a virtual wire, you must apply a security policy rule that allows the traffic to pass through. For example, apply a security policy rule that allows an application such as BGP or OSPF. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/layer-2-and-layer-3-packets-over-a-virtual-wire#id176TE0F0UDU_id176TE000DXC

confusionOptions: CDE

CDE links from nose999, TAKUM1y and al12345 point that clearly