Palo Alto Networks Network Security Analyst (NetSec-Analyst) Exam Materials-Question 48 Discussion
Comment Image Comment Image Comment Image

A new firewall has been added to Panorama. After entering the firewall serial number and configuring the Panorama IP address on the firewall, the device still appears as "disconnected" under Panorama Managed Devices. Given that both Panorama and the firewall are on the same subnet, what are two causes for this behavior? (Choose two answers)

  • A. Panorama policy and objects are disabled in the firewall under Panorama settings.
  • B. The firewall does not have a management profile to allow the Panorama IP address.
  • C. Panorama IP is not allowed in the firewall management interface permitted IP list.
  • D. Panorama is running on a PAN-OS version lower than the firewall.
Correct Answer: B,C

Brave-Dump Clients Votes

CD 100%

Comments



Anonymous User 2026-05-01 22:43:47

Selected Answers: C, D


Correct answers are C and D

A fundamental rule of Palo Alto Networks management is that Panorama must be running a version of PAN-OS that is equal to or higher than the firewalls it manages.

Option B is wrong because a management profile is used to allow services (like HTTPS, SSH or Ping) on data plane interfaces.