exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 256 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 256
Topic #: 1
[All PCNSE Questions]

What happens when an A/P firewall cluster synchronizes IPsec tunnel security associations (SAs)?

  • A. Phase 2 SAs are synchronized over HA2 links.
  • B. Phase 1 and Phase 2 SAs are synchronized over HA2 links.
  • C. Phase 1 SAs are synchronized over HA1 links.
  • D. Phase 1 and Phase 2 SAs are synchronized over HA3 links.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
bartbernini
Highly Voted 1 year, 10 months ago
Selected Answer: A
From the Palo Alto documentation below, "when a VPN is terminated on a Palo Alto firewall HA pair, not all IPSEC related information is synchronized between the firewalls... This is an expected behavior. IKE phase 1 SA information is NOT synchronized between the HA firewalls." And from the second link, "Data link (HA2) is used to sync sessions, forwarding tables, IPSec security associations, and ARP tables between firewalls in the HA pair. Data flow on the HA2 link is always unidirectional (except for the HA2 keep-alive). It flows from the active firewall to the passive firewall." https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAuZCAW&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail https://help.aryaka.com/display/public/KNOW/Palo+Alto+Networks+NFV+Technical+Brief
upvoted 18 times
...
Marcyy
Highly Voted 2 years ago
Correct. Only Phase2 are Synced.
upvoted 7 times
...
Metgatz
Most Recent 6 days, 4 hours ago
Correct option is A : This is an expected behavior. IKE phase 1 SA information is NOT synchronized between the HA firewalls - https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAuZCAW
upvoted 1 times
...
gc999
1 month, 2 weeks ago
Selected Answer: A
I believe A is the answer https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXGCA0#:~:text=Session%20states-,IPSec%20SAs,-MAC%20Tables
upvoted 1 times
...
Omid2022
1 month, 2 weeks ago
Selected Answer: A
Study guide page 194: The HA2 link is used to synchronize sessions, forwarding tables, IPSec security associations and ARP tables between firewalls in an HA pair. Data flow on the HA2 link is always unidirectional (except for the HA2 keep-alive); it flows from the active or active-primary firewall to the passive or active-secondary firewall. The HA2 link is a Layer 2 link, and it uses ether type 0x7261 by default
upvoted 1 times
...
jhonelo2011
3 months ago
Selected Answer: B
I am going with B, Phase 1 and 2 are part of IPsec VPN tunnels.
upvoted 1 times
...
TAKUM1y
1 year, 1 month ago
Selected Answer: B
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/high-availability/ha-concepts/ha-links-and-backup-links#id1df2d565-1765-4666-83b0-87652318e06f
upvoted 2 times
yup101
1 year ago
It's A. bertbernini URL explains it pretty well.
upvoted 2 times
...
ericli87
8 months, 1 week ago
Phase1 is IKE SA. Phase 2 is IPSEC SA.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago