PSE-STRATADC · Question #13
Which configuration is required in NSX for Panorama to use the tags from security groups in dynamic address groups?
The correct answer is A. Create security groups only. In the NSX-Panorama integration, simply creating security groups in NSX is all that's required - Panorama automatically pulls the associated tags from those groups to populate Dynamic Address Groups (DAGs) through the registered VM/tag synchronization mechanism built into the…
Question
Which configuration is required in NSX for Panorama to use the tags from security groups in dynamic address groups?
Options
- ACreate security groups only.
- BCreate security groups and mark them as exchangeable.
- CCreate security groups with tags marked as shareable.
- DCreate security groups and use them in an NSX-to-Palo Alto Networks redirection policy.
How the community answered
(27 responses)- A93% (25)
- B4% (1)
- C4% (1)
Explanation
In the NSX-Panorama integration, simply creating security groups in NSX is all that's required - Panorama automatically pulls the associated tags from those groups to populate Dynamic Address Groups (DAGs) through the registered VM/tag synchronization mechanism built into the integration. No extra marking, flagging, or policy association is needed to enable this tag-sharing behavior.
Why the distractors are wrong:
- B - "Exchangeable" is not a real NSX configuration attribute for security groups; this option invents a non-existent requirement.
- C - Tags in NSX do not have a "shareable" flag; tag visibility to Panorama is automatic once the integration is configured, not controlled per-tag.
- D - Redirection policies control traffic steering from NSX to Palo Alto Networks firewalls, which is a separate function unrelated to making tags available for dynamic address groups.
Memory tip: Think "create = complete." The moment an NSX security group exists, Panorama can see its tags - no extra steps. If a distractor adds an adjective (exchangeable, shareable) or an additional action (redirection policy), it's almost certainly wrong, because the integration is designed to work automatically with standard security group creation.
Topics
Community Discussion
No community discussion yet for this question.