Deployment Flashcards

1
Q

Where can be the VM-Series deploymed? (8)

A
  • VMware vSphere Hypervisor (ESXi)
  • VMware vCloud Air
  • VMware NSX-T
  • Amazon Web Services (AWS)
  • Google Cloud Platform (GCP)
  • Microsoft Azure
  • Kernel Virtualization Module (KVM)
  • Microsoft Hyper-V
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What do the virtual firewalls need to match in order to be able to form an HA pair? (3)

A
  1. must be deployed on the same type of hypervisor
  2. have identical hardware resources (such as CPU cores/network interfaces) assigned to them
  3. have the set same of licenses/subscriptions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Where can be the VM firewall deployed in active/active state?

A
  • in virtual wire and Layer 3 deployments on some private cloud hypervisors
  • recommended only if each firewall needs its own routing instances and you require full, real-time redundancy out of both firewalls all the time
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Do any of the public cloud providers support active/active deployment?

A

no

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Why NSX-V doesn’t support any of the HA features?

A

HA is achieved through the NSX-T feature called service health check

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are PAN-OS XFR releases?

A

PAN-OS for VM-Series firewalls only; can include new features and bug fixes for VM-Series firewalls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What MAC addresses does the VM-Series use by default on its created L3 interfaces?

A
  • those assigned by the hypervisor
  • the firewall can then use the hypervisor assigned MAC address in its ARP responses
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Is there an option to enable or disable the use of hypervisor assigned MAC addresses on AWS and Azure?

A

no, it is enabled by default for both platforms and cannot be disabled

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

if hypervisor assigned MAC address functionality is enabled on the VM-Series firewall, what needs to be considered in terms of IPv6 Address on an Interface in active/passive HA configuration?

A

Layer 3 interfaces using IPv6 addresses must not use the EUI-64 generated address as the interface identifier (Interface ID), as the IP address is not stati, as it results in a change in the IP address for the HA peer when the hardware hosting the VM-Series firewall changes on failover, which leads to an HA failure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

if hypervisor assigned MAC address functionality is enabled on the VM-Series firewall, what needs to be considered in terms of Lease on an IP Address when changing MAC address?

A

when the MAC address changes, DHCP client, DHCP relay and PPPoE interfaces might release the IP address because the original IP address lease could terminate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

if hypervisor assigned MAC address functionality is enabled on the VM-Series firewall, what needs to be considered in terms of MAC address and Gratuitous ARP in HA?

A

because each dataplane interface has a unique MAC address, when a failover occurs, the now active VM-Series firewall must send a gratuitous ARP so that neighboring devices can learn the updated MAC/IP address pairing - make sure to disable the anti-ARP poisoning feature on the internetworking devices, if required

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

When deployed in public cloud, the firewall natively publishes metrics to monitoring systems in the respective public clouds. What are the names of the monitoring systems in AWS, Azure nad GCP?

A
  • AWS = CloudWatch
  • Azure = Application Insights
  • GCP = Stackdriver
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Why does firewall natively publish certain metrics to cloud monitoring systems in public clouds?

A

to assess firewall performance and usage patterns so that you can set alarms and take action to automate events such as launching or terminating instances of the VM-Series firewalls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How are the public cloud metrics published to firewalls?

A

through content updates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are some of the metrics published by the firewall?

A
  • Dataplane CPU Utilization (%)
  • panSessionConnectionsPerSecond
  • Sessions Active
  • panSessionThroughputKbps
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

For which actions does the management interface always need to be used on the VM-Series?

A
  • licensing
  • bootstrapping from a cloud storage location such as AWS S3 bucket, Azure storage file service, or Google storage bucket
  • publishing PAN-OS metrics to a cloud monitoring service such as AWS CloudWatch, Azure Application Insights or Google Stackdriver