nerdexam
Palo_Alto_Networks

PSE-STRATADC · Question #11

A network administrator is working on a VMware NSX installation with VM-1000-HV firewalls The administrator has created a security group that is populated with VMs The administrator is trying to…

The correct answer is D. Check the NSX Security policy to ensure the security group has been used in a policy. In the Palo Alto Networks/VMware NSX integration, NSX only exports security group information to Panorama when that security group is actively referenced in an NSX Security Policy (Service Composer). If the security group exists in NSX but isn't used in any policy, NSX simply…

VM-Series Deployment on VMware NSX

Question

A network administrator is working on a VMware NSX installation with VM-1000-HV firewalls The administrator has created a security group that is populated with VMs The administrator is trying to create a Dynamic Address Group in Panorama, but the security group is not showing. Which task should the administrator perform first?

Options

  • AGo into vCenter/NSX and push the objects to Panorama
  • BDelete and re-add the security group.
  • CGo into Panorama and synchronize the Address objects with NSX
  • DCheck the NSX Security policy to ensure the security group has been used in a policy.

How the community answered

(52 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    10% (5)
  • D
    83% (43)

Explanation

In the Palo Alto Networks/VMware NSX integration, NSX only exports security group information to Panorama when that security group is actively referenced in an NSX Security Policy (Service Composer). If the security group exists in NSX but isn't used in any policy, NSX simply won't make it available to Panorama - which is exactly why the Dynamic Address Group population fails. Option A is wrong because there is no manual "push objects" workflow from vCenter/NSX to Panorama in this integration; synchronization is event-driven. Option B (delete/re-add) is unnecessary troubleshooting noise that doesn't address the root cause. Option C (synchronizing in Panorama) fails because Panorama can only sync what NSX has exposed - if the security group isn't tied to a policy, there's nothing for Panorama to pull.

Memory tip: Think "NSX won't share what it doesn't USE." A security group must be referenced in an NSX security policy before NSX will surface it to Panorama for Dynamic Address Group consumption.

Topics

#Dynamic Address Group#Panorama#NSX security group#troubleshooting

Community Discussion

No community discussion yet for this question.

Full PSE-STRATADC Practice