PCNSE · Question #873
An enterprise network security team is deploying VM-Series firewalls in a multi-cloud environment. Some firewalls are deployed in VMware NSX-V, while others are in AWS, and all are centrally managed…
The correct answer is D. Panorama does not support policy inheritance across device groups containing firewalls deployed. Panorama device group hierarchy allows parent-child policy inheritance, but this mechanism is designed for firewalls of compatible deployment types. Panorama does not support policy inheritance across device groups that contain firewalls deployed on fundamentally different…
Question
An enterprise network security team is deploying VM-Series firewalls in a multi-cloud environment. Some firewalls are deployed in VMware NSX-V, while others are in AWS, and all are centrally managed using Panorama with the appropriate plugins installed. The team wants to streamline policy management by organizing the firewalls into device groups in which the AWS- based firewalls act as a parent device group, while the NSX-V firewalls are configured as a child device group to inherit Security policies. However, after configuring the device group hierarchy and attempting to push configurations, the team receives errors, and policy inheritance is not functioning as expected. What is the most likely cause of this issue?
Options
- APanorama must use the same plugin version numbers for both AWS and NSX-V environments
- BPanorama requires the objects to be overridden in the child device group before firewalls in
- CPanorama by default does not allow different hypervisors in parent/child device groups, but this
- DPanorama does not support policy inheritance across device groups containing firewalls deployed
How the community answered
(16 responses)- A13% (2)
- C6% (1)
- D81% (13)
Explanation
Panorama device group hierarchy allows parent-child policy inheritance, but this mechanism is designed for firewalls of compatible deployment types. Panorama does not support policy inheritance across device groups that contain firewalls deployed on fundamentally different platforms managed by different plugins (e.g., the AWS plugin versus the VMware NSX-V plugin). Each plugin manages its own device group context, and the policy push and inheritance model cannot span across these plugin boundaries. Therefore, mixing AWS-managed firewalls as the parent with NSX-V-managed firewalls as the child in an inheritance hierarchy is not supported, which explains the errors and failed inheritance.
Topics
Community Discussion
No community discussion yet for this question.