PCNSE · Question #348
An engineer is designing a deployment of multi-vsys firewalls. What must be taken into consideration when designing the device group structure?
The correct answer is C. Multiple vsys and firewalls can be assigned to a device group, and a multi-vsys firewall can have. When designing a Panorama device group structure for multi-vsys firewalls, it's crucial to understand that device groups can manage multiple firewalls, and each virtual system (vsys) on a multi-vsys firewall is treated as a distinct logical device that can be assigned to device…
Question
An engineer is designing a deployment of multi-vsys firewalls. What must be taken into consideration when designing the device group structure?
Options
- AMultiple vsys and firewalls can be assigned to a device group, and a multi-vsys firewall must have
- BOnly one vsys or one firewall can be assigned to a device group, except for a multi-vsys firewall,
- CMultiple vsys and firewalls can be assigned to a device group, and a multi-vsys firewall can have
- DOnly one vsys or one firewall can be assigned to a device group, and a multi-vsys firewall can
How the community answered
(57 responses)- A2% (1)
- C95% (54)
- D4% (2)
Why each option
When designing a Panorama device group structure for multi-vsys firewalls, it's crucial to understand that device groups can manage multiple firewalls, and each virtual system (vsys) on a multi-vsys firewall is treated as a distinct logical device that can be assigned to device groups.
The statement's implied 'must have' in the incomplete sentence suggests a lack of flexibility for multi-vsys assignment, which is generally not the case in Panorama deployments.
This statement is incorrect because Panorama device groups are designed to manage policies across multiple devices and virtual systems, not just one.
Multiple vsys and firewalls can be assigned to a device group, as Panorama treats each vsys on a multi-vsys firewall as a separate logical entity that can be managed within a device group, alongside physical firewalls.
This statement is incorrect as Panorama device groups support managing multiple firewalls and virtual systems within a single group, offering scalability beyond a single device.
Concept tested: Panorama Device Group structure with multi-vsys firewalls
Source: https://docs.paloaltonetworks.com/panorama/10-2/panorama-admin/manage-firewalls/device-groups
Topics
Community Discussion
No community discussion yet for this question.