Q: 6
An engineer at a managed services provider is updating an application that allows its customers to
request firewall changes to also manage SD-WAN. The application will be able to make any approved
changes directly to devices via API.
What is a requirement for the application to create SD-WAN interfaces?
Options
Discussion
Yeah, you got it. B is the way since SD-WAN interface creation needs the REST API endpoint on the firewall itself. Seen similar in docs, but open to correction if Palo changes something.
C is wrong, B. You need REST API on the firewall itself for sdwanInterfaces, not Panorama or XML calls. XML was more common in older workflows, but for direct interface creation this points to B. If someone has different info, let's hear it.
C or D here. Both mention XML API, which I've seen referenced in some older admin guides for SD-WAN profile management. If the app is tied to Panorama device-based changes using XML, I'd probably say C is closer. Pretty sure the official guide has more on this, might want to double-check there before committing.
B
B is right since the app must talk to the firewall REST API directly. D looks tempting if you remember older XML workflows, but current SD-WAN interface creation is REST-based on the firewall itself. Pretty sure that's what all the latest docs show, happy to hear another angle though.
C imo. If they're using XML API with Panorama, then the
sdwanprofiles/interfaces parameter on Panorama could work for managing SD-WAN interfaces from a higher level. I thought direct device config was more REST-focused, but I've seen older docs mention XML calls too. Not 100% sure, anyone else run into this?B , REST API with sdwanInterfaces on the firewall is the right call since the app needs to create interfaces directly. D is a common trap from older XML API references, but REST is required here. Open to other takes but pretty sure it’s B.
B , official docs and exam guides both point to the REST API's sdwanInterfaces on firewall for this use. If you need more hands-on confirmation, lab it out or check the admin guide.
D not B. If you focus on XML API angle, D looks like a reasonable trap since it references "InterfaceProfiles/sdwan" right on the device. I think some older docs mention that parameter, so might throw folks off.
B tbh
Be respectful. No spam.