Cybersecurity-Practitioner Network Security Practice Question
An administrator is troubleshooting a BGP routing peer connection between the Palo Alto Networks firewall and an external provider router. The BGP session is stuck in the 'Connect' state. Inspection of system logs indicates TCP port 179 packets sent by the firewall are being transmitted, but no SYN-ACK is received. Which troubleshooting step or feature verification should be performed first?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that a Security policy rule with application 'bgp' (or service tcp-179) from the external zone to 'zone: 'to-firewall'' permits control plane traffic, or check Zone Protection / Management Profile settings.
BGP uses TCP port 179. If SYN packets are sent but no SYN-ACK is returned, the issue is either upstream filtering, incorrect peer IP, or Zone Protection / Security policies blocking the control plane traffic destined for the firewall's routing daemon.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify that a Security policy rule with application 'bgp' (or service tcp-179) from the external zone to 'zone: 'to-firewall'' permits control plane traffic, or check Zone Protection / Management Profile settings.
Why this is correct
Control plane traffic destined for the firewall itself from external zones requires appropriate zone protection, management profile, or security policy evaluation depending on interface configuration.
- ✗
Reconfigure the Virtual Wire interface pair to handle BGP encapsulation headers.
Why it's wrong here
BGP is a Layer 3 routing protocol and requires Layer 3 interfaces, not Virtual Wire.
- ✗
Restart the Management server process using the CLI command 'debug software restart management-server'.
Why it's wrong here
BGP routing daemons run on the data plane/routing engine (RTE), not the management server.
- ✗
Convert the BGP peer to OSPFv3 protocol.
Why it's wrong here
Switching routing protocols does not solve underlying packet filtering or routing misconfigurations.
Visual reference
About these practice questions
Courseiva writes every Cybersecurity-Practitioner question from scratch — 206 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This Cybersecurity-Practitioner practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Practitioner exam.