PSE-STRATADC · Question #27
In PAN-OS, which three NSX features can be pushed from Panorama? (Choose three )
The correct answer is A. user IP mappings C. multiple authorization codes E. security groups. In the PAN-OS/VMware NSX integration, Panorama serves as the centralized management plane and can push user IP mappings (A) to synchronize User-ID data across the environment, multiple authorization codes (C) to register Palo Alto Networks services within NSX, and security…
Question
In PAN-OS, which three NSX features can be pushed from Panorama? (Choose three )
Options
- Auser IP mappings
- Bsteering rules
- Cmultiple authorization codes
- Dsecurity group assignments of VMs
- Esecurity groups
How the community answered
(27 responses)- A89% (24)
- B7% (2)
- D4% (1)
Explanation
In the PAN-OS/VMware NSX integration, Panorama serves as the centralized management plane and can push user IP mappings (A) to synchronize User-ID data across the environment, multiple authorization codes (C) to register Palo Alto Networks services within NSX, and security groups (E) as dynamic objects that firewalls use in policy enforcement - all three flow outward from Panorama into the NSX ecosystem.
Why the distractors are wrong:
- B (Steering rules) are configured within NSX itself to redirect traffic to the NGFW; they originate in NSX, not Panorama.
- D (Security group assignments of VMs) are managed by the vCenter/NSX administrator - which VMs belong to which group is an NSX/vSphere operation, not a Panorama push.
Memory tip: Think of Panorama's role as pushing identity and policy ingredients - who users are (A), what security groups exist (E), and license/registration tokens (C). Anything that describes the physical/virtual network topology (steering, VM assignments) lives in NSX, not Panorama.
Topics
Community Discussion
No community discussion yet for this question.