nerdexam
Palo_Alto_Networks

PSE-STRATADC · Question #14

How does the Palo Alto Networks NGFW integrate with Arista Networks Macro-Segmentation Service?

The correct answer is D. Arista owns the Security policy. It can extend the concept of fine-grained intra-hypervisor. Option D is correct because in Arista's Macro-Segmentation Service (MSS) architecture, Arista retains ownership of the network-level segmentation policy - deciding which traffic flows are redirected to the NGFW for inspection. MSS extends the segmentation concept beyond…

SDN Integration

Question

How does the Palo Alto Networks NGFW integrate with Arista Networks Macro-Segmentation Service?

Options

  • AArista supports all hardware models of the Palo Alto Networks NGFW natively.
  • BArista allows standalone non-HA firewalls to be attached to a service leaf switch. You must
  • CArista CloudVision obtains relevant rules from Panorama through API and programs the Arista
  • DArista owns the Security policy. It can extend the concept of fine-grained intra-hypervisor

How the community answered

(54 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    6% (3)
  • D
    91% (49)

Explanation

Option D is correct because in Arista's Macro-Segmentation Service (MSS) architecture, Arista retains ownership of the network-level segmentation policy - deciding which traffic flows are redirected to the NGFW for inspection. MSS extends the segmentation concept beyond physical switches down to the hypervisor level (intra-hypervisor), enabling east-west traffic to be steered to a pool of Palo Alto NGFWs without requiring the firewall to own or redefine the overarching segmentation policy.

Why the distractors are wrong:

  • A is false because MSS does not natively support all Palo Alto hardware models - only validated/supported platforms are compatible.
  • B is incorrect because MSS requires HA firewall pairs attached to service leaf switches; standalone non-HA deployments are not the supported model for this integration.
  • C describes a non-existent flow - CloudVision does not pull firewall rules from Panorama via API to program Arista switches; policy steering is managed at the EOS/fabric level, not sourced from Panorama.

Memory tip: Think of MSS as a traffic cop (Arista) directing cars (flows) to a checkpoint (PAN NGFW). The cop owns the road rules (macro-segmentation), not the checkpoint - so Arista owns the policy directing traffic, while PAN inspects it. MSS = Macro = Managed by Arista.

Topics

#Arista#macro-segmentation#NGFW integration#MSS

Community Discussion

No community discussion yet for this question.

Full PSE-STRATADC Practice