PCNSE Exam QuestionsBrowse all questions from this exam

PCNSE Exam - Question 318


An engineer wants to implement the Palo Alto Networks firewall in VWire mode on the internet gateway and wants to be sure of the functions that are supported on the vwire interface.

What are three supported functions on the VWire interface? (Choose three.)

Show Answer
Correct Answer: A,C,D,E

The Palo Alto Networks virtual wire (VWire) interface supports SSL Decryption, QoS, and NAT functions. You wouldn't use a virtual wire for IPSec because it does not support protocols that require Layer 2 or Layer 3 addresses. Similarly, OSPF, being a routing protocol, is also not supported since VWire interfaces do not participate in routing functions.

Discussion

16 comments
Sign in to comment
nose999Options: CDE
Sep 6, 2022

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces

al12345Options: CDE
Sep 21, 2022

The virtual wire supports blocking or allowing traffic based on virtual LAN (VLAN) tags, in addition to supporting security policy rules, App-ID, Content-ID, User-ID, decryption, LLDP, active/passive and active/active HA, QoS, zone protection (with some exceptions), non-IP protocol protection, DoS protection, packet buffer protection, tunnel content inspection, and NAT. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/virtual-wire-interfaces

TAKUM1yOptions: CDE
Oct 27, 2022

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/virtual-wire-interfaces "The virtual wire supports blocking or allowing traffic based on virtual LAN (VLAN) tags, in addition to supporting security policy rules, App-ID, Content-ID, User-ID, decryption, LLDP, active/passive and active/active HA, QoS, zone protection (with some exceptions), non-IP protocol protection, DoS protection, packet buffer protection, tunnel content inspection, and NAT."

confusionOptions: CDE
Oct 29, 2022

CDE links from nose999, TAKUM1y and al12345 point that clearly

awtsuritacunaOptions: BDE
Dec 6, 2022

Options: B/D/E - The virtual wire allows the firewall to maintain a transparent presence acting as a pass-through link, while still providing security, NAT, and QoS services. - In order for routing (Layer 3) control packets to pass through a virtual wire, you must apply a security policy rule that allows the traffic to pass through. For example, apply a security policy rule that allows an application such as BGP or OSPF. https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces/layer-2-and-layer-3-packets-over-a-virtual-wire#id176TE0F0UDU_id176TE000DXC

aatechlerOptions: CDE
Dec 21, 2022

You wouldn’t use a virtual wire deployment for interfaces that need to support switching, VPN tunnels, or routing because they require a Layer 2 or Layer 3 address. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-networking-admin/configure-interfaces/virtual-wire-interfaces

DenskyDenOptions: CDE
Jan 17, 2023

CDE. The virtual wire supports blocking or allowing traffic based on virtual LAN (VLAN) tags, in addition to supporting security policy rules, App-ID, Content-ID, User-ID, "DECRYPTION", LLDP, active/passive and active/active HA, "QOS", zone protection (with some exceptions), non-IP protocol protection, DoS protection, packet buffer protection, tunnel content inspection, and "NAT".

GohanF2Options: CDE
Feb 11, 2023

It is CDE.

sujssOptions: CDE
Apr 29, 2023

I guess easiest approach for this is discard anything that needs an IP (or MAC) as Vwire interfaces do not support IP or MAC

dgonzOptions: CDE
Sep 5, 2023

CDE are correct

NawdaOptions: CDE
Sep 14, 2023

no switching or routing for Vwire

XuziOptions: CDE
Nov 14, 2023

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/networking/configure-interfaces/virtual-wire-interfaces

MetgatzOptions: CDE
Dec 11, 2023

CDE are the correcto options

JRKhanOptions: CDE
Jan 15, 2024

CDE is correct. Vwire interfaces cannot be used as IPsec termination points.

123XYZTOptions: CDE
Jun 17, 2024

CDE A is incorrect because: You wouldn’t use a virtual wire deployment for interfaces that need to support switching, VPN tunnels, or routing because they require a Layer 2 or Layer 3 address.

ali_sh85Options: CDE
Jul 17, 2024

The virtual wire supports the blocking or allowing of traffic based on the virtual LAN (VLAN) tags. The virtual wire also supports Security policy rules, App-ID, Content-ID, User-ID, decryption, LLDP, active/passive and active/active high availability (HA), QoS, zone protection (with some exceptions), non-IP protocol protection, denial of service (DoS) protection, packet buffer protection, tunnel content inspection,and NAT.