Palo Alto Networks NGFW-Engineer Exam - Topic 3 Question 27 Discussion
A network security engineer is designing a resilient architecture for inspecting traffic in Google Cloud Platform (GCP). The design must ensure that firewall service is maintained even if a single GCP zone becomes unavailable.Which architecture should be used for the VM-Series firewalls in this use case?
C) Instance group of VM-Series firewalls spread across multiple zones with traffic routed to them by a GCP Internal Load Balancer
A) Ansible playbook that monitors the health of the primary firewall and launches a new one in a different zone when a failure is detected
B) Single, large VM-Series firewall in one zone that is configured for live migration to another zone upon failure
D) PAN-OS active/active high availability (HA) cluster configured with dedicated HA interfaces in a shared VPC
Currently there are no comments in this discussion, be the first to comment!