PCNSE · Question #683
An engineer discovers the management interface is not routable to the User-ID agent. What configuration is needed to allow the firewall to communicate to the User-ID agent?
The correct answer is C. Create a custom service route for the UID Agent. To allow the firewall to communicate with the User-ID agent, you need to configure a custom service route for the UID Agent23. A custom service route allows you to specify which interface and source IP address the firewall uses to connect to a specific destination service. By def
Question
An engineer discovers the management interface is not routable to the User-ID agent. What configuration is needed to allow the firewall to communicate to the User-ID agent?
Options
- AAdd a Policy Based Forwarding (PBF) policy to the User-ID agent IP
- BCreate a NAT policy for the User-ID agent server
- CCreate a custom service route for the UID Agent
- DAdd a static route to the virtual router
How the community answered
(37 responses)- A3% (1)
- B5% (2)
- C81% (30)
- D11% (4)
Explanation
To allow the firewall to communicate with the User-ID agent, you need to configure a custom service route for the UID Agent23. A custom service route allows you to specify which interface and source IP address the firewall uses to connect to a specific destination service. By default, the firewall uses its management interface for services such as User-ID, but you can override this behavior by creating a custom service route. To configure a custom service route for the UID Agent, you need to do the following steps: Go to Device > Setup > Services and click Service Route Configuration. In the Service column, select User-ID Agent from the drop-down list. In the Interface column, select an interface that can reach the User-ID agent server from the drop-down list. In the Source Address column, select an IP address that belongs to that interface from the drop- Click OK and Commit your changes.
Topics
Community Discussion
No community discussion yet for this question.