Courseiva
Network SecurityhardMultiple ChoiceObjective-mapped

Cybersecurity-Practitioner Network Security Practice Question

An administrator is troubleshooting a BGP routing peer connection between the Palo Alto Networks firewall and an external provider router. The BGP session is stuck in the 'Connect' state. Inspection of system logs indicates TCP port 179 packets sent by the firewall are being transmitted, but no SYN-ACK is received. Which troubleshooting step or feature verification should be performed first?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify that a Security policy rule with application 'bgp' (or service tcp-179) from the external zone to 'zone: 'to-firewall'' permits control plane traffic, or check Zone Protection / Management Profile settings.

BGP uses TCP port 179. If SYN packets are sent but no SYN-ACK is returned, the issue is either upstream filtering, incorrect peer IP, or Zone Protection / Security policies blocking the control plane traffic destined for the firewall's routing daemon.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Verify that a Security policy rule with application 'bgp' (or service tcp-179) from the external zone to 'zone: 'to-firewall'' permits control plane traffic, or check Zone Protection / Management Profile settings.

    Why this is correct

    Control plane traffic destined for the firewall itself from external zones requires appropriate zone protection, management profile, or security policy evaluation depending on interface configuration.

  • Reconfigure the Virtual Wire interface pair to handle BGP encapsulation headers.

    Why it's wrong here

    BGP is a Layer 3 routing protocol and requires Layer 3 interfaces, not Virtual Wire.

  • Restart the Management server process using the CLI command 'debug software restart management-server'.

    Why it's wrong here

    BGP routing daemons run on the data plane/routing engine (RTE), not the management server.

  • Convert the BGP peer to OSPFv3 protocol.

    Why it's wrong here

    Switching routing protocols does not solve underlying packet filtering or routing misconfigurations.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva writes every Cybersecurity-Practitioner question from scratch — 206 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cybersecurity-Practitioner practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Practitioner exam.