PCNSE Exam QuestionsBrowse all questions from this exam

PCNSE Exam - Question 590


Which conditions must be met when provisioning a high availability (HA) cluster? (Choose two.)

Show Answer
Correct Answer: AB

When provisioning a high availability (HA) cluster, the cluster members must be the same firewall model and run the same PAN-OS version to ensure compatibility and stability. Additionally, the HA cluster members must share the same zone names to enable seamless session failover between cluster members. These conditions ensure that the HA cluster functions correctly and provides the desired fault tolerance.

Discussion

6 comments
Sign in to comment
b53fdf1Options: AB
Mar 28, 2024

Provisioning Requirements and Best Practices HA cluster members must be the same firewall model and run the same PAN-OS® version. HA cluster members must share the same zone names in order for sessions to successfully fail over to another cluster member. https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/ha-clustering-best-practices-and-provisioning

nebulanerd
Jun 23, 2024

Yes! Perfect!

jaypogi16Options: AB
Apr 1, 2024

AB is the answer

MostafaNawarOptions: AB
Apr 23, 2024

A and B sure https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/ha-clustering-best-practices-and-provisioning

hcirOptions: AB
May 4, 2024

hsci is used to sync sessions not actual traffic which is the case for the HA4 interfaces of a cluster. Panorama is recommended to sync the config but not mandatory. So A and B

0d2fdfaOptions: AB
Jun 3, 2024

https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/ha-clustering-best-practices-and-provisioning

nebulanerdOptions: AB
Jun 23, 2024

A&B - It should be noted that option D is not a mandatory requirement; rather, it represents a best practice for devices on platforms that have dedicated HA ports. "When connecting two Palo Alto Networks® firewalls in a high availability (HA) configuration, 'WE RECOMMEND' that you use the dedicated HA ports for HA Links and Backup Links." "For firewalls without dedicated HA interfaces, such as the PA-200 and PA-400 Series, it is required to configure a data port as a HA interface." https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/high-availability/ha-concepts/ha-links-and-backup-links/ha-ports-on-the-pa-7000-series-firewall