PCNSE · Question #407
A company wants to use their Active Directory groups to simplify their Security policy creation from Panorama. Which configuration is necessary to retrieve groups from Panorama?
The correct answer is D. Configure a master device within the device groups. To use Active Directory groups in Panorama security policies, Panorama must have a way to retrieve and display those groups. This is accomplished by configuring a master device within the device group. The master device is a managed PAN-OS firewall that has User-ID and group…
Question
A company wants to use their Active Directory groups to simplify their Security policy creation from Panorama. Which configuration is necessary to retrieve groups from Panorama?
Options
- AConfigure an LDAP Server profile and enable the User-ID service on the management interface.
- BConfigure a group mapping profile to retrieve the groups in the target template.
- CConfigure a Data Redistribution Agent to receive IP User Mappings from User-ID agents.
- DConfigure a master device within the device groups.
How the community answered
(21 responses)- A19% (4)
- B10% (2)
- C29% (6)
- D43% (9)
Explanation
To use Active Directory groups in Panorama security policies, Panorama must have a way to retrieve and display those groups. This is accomplished by configuring a master device within the device group. The master device is a managed PAN-OS firewall that has User-ID and group mapping already configured and communicating with Active Directory. Panorama queries this master device to pull the list of available AD groups for use in policy. LDAP Server Profiles (A) and group mapping (B) are configured on the individual firewalls or in templates, but the Panorama device group still needs a master device designated to supply group data. A Data Redistribution Agent (C) deals with IP-to-user mappings, not group retrieval for policy creation.
Topics
Community Discussion
No community discussion yet for this question.