An administrator needs to implement an NGFW between their DMZ and Core network. EIGRP Routing between the two environments is required. Which interface type would support this business requirement?
A.
Virtual Wire interfaces to permit EIGRP routing to remain between the Core and DMZ
B.
Layer 3 or Aggregate Ethernet interfaces, but configuring EIGRP on subinterfaces only
C.
Tunnel interfaces to terminate EIGRP routing on an IPsec tunnel (with the GlobalProtect License to support LSVPN and EIGRP protocols)
D.
Layer 3 interfaces, but configuring EIGRP on the attached virtual router
To implement a Palo Alto Networks Next-Generation Firewall (NGFW) between your DMZ and Core network while ensuring EIGRP routing continues to function, you need an interface type that allows the routing protocol to pass through without requiring the firewall to support EIGRP directly. Given that PAN-OS does not natively support EIGRP, the best option is likely Virtual Wire interfaces, which operate transparently and let EIGRP traffic flow as if the firewall isn’t there.
The correct answer is:
**D. Layer 3 interfaces, but configuring EIGRP on the attached virtual router**
### Key Configuration Steps:
1. Assign **Layer 3 interfaces** to zones (e.g., DMZ and Core).
2. Enable **EIGRP** in the Virtual Router and advertise networks.
The correct answer is:
**D. Layer 3 interfaces, but configuring EIGRP on the attached virtual router**
### Explanation:
To support **EIGRP routing** between the DMZ and Core networks on a Palo Alto NGFW:
1. **Layer 3 interfaces** must be used (EIGRP is a Layer 3 routing protocol).
2. EIGRP is configured in the **Virtual Router**, not on individual interfaces.
This section is not available anymore. Please use the main Exam Page.PCNSE Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Edu147
Highly Voted 6 years agoGeoGR2022
Highly Voted 3 years, 2 months agoNico1973
Most Recent 1 month, 1 week agoNico1973
1 month, 1 week agoNico1973
2 months, 4 weeks agocumzle_com
2 months, 3 weeks agoALCOSTA35
9 months agoMarshpillowz
1 year, 6 months agovj77
4 years, 3 months agoUmaShankar
4 years, 9 months agoalpha520
5 years, 2 months agoAhmad_Zahran
5 years, 3 months agoasmaam
5 years, 4 months ago