What this objective tests
PCNSE Troubleshoot — Key Topics
Diagnose PAN-OS traffic, GlobalProtect, decryption, commit, and HA failures using CLI tools like show session all, test url, and less mp-log. Most important: read the specific log or counter that pinpoints the failing stage before changing config.
- Reading 'show session all filter' and 'test security-policy-match' output to trace dropped traffic
- Using 'show system logdb-quota' and log forwarding to isolate logging pipeline failures
- Diagnosing GlobalProtect tunnel failures via 'show global-protect-gateway statistics' and gateway logs
- Interpreting HA state with 'show high-availability state' and resolving split-brain or suspended peers