nerdexam
Palo_Alto_Networks

PSE-STRATADC · Question #47

Which configuration is required to share NSX security groups as tags to be used by Dynamic Address Groups in a non-NSX firewall?

The correct answer is B. a User-ID agent on a Windows domain server. A User-ID agent installed on a Windows server acts as the redistribution bridge between VMware NSX and non-NSX firewalls: it connects to NSX Manager, collects security group membership data, converts that data into IP address tags, and then pushes those tags to the non-NSX…

VMware NSX Integration

Question

Which configuration is required to share NSX security groups as tags to be used by Dynamic Address Groups in a non-NSX firewall?

Options

  • Anotify device groups within VMware Services Manager
  • Ba User-ID agent on a Windows domain server
  • CVMware Information Sources
  • Dnone, sharing happens by default

How the community answered

(57 responses)
  • A
    11% (6)
  • B
    81% (46)
  • C
    5% (3)
  • D
    4% (2)

Explanation

A User-ID agent installed on a Windows server acts as the redistribution bridge between VMware NSX and non-NSX firewalls: it connects to NSX Manager, collects security group membership data, converts that data into IP address tags, and then pushes those tags to the non-NSX firewall so Dynamic Address Groups can reference them. Without this intermediary, the non-NSX firewall has no direct mechanism to receive NSX security group information.

Why the distractors are wrong:

  • A (VMware Services Manager): Not a real component in this workflow - this is a fabricated distractor with no defined role in NSX-to-firewall tag sharing.
  • C (VMware Information Sources): This is a real Palo Alto feature for pulling general VM inventory directly from vCenter, but it does not handle the redistribution of NSX security group tags to non-NSX firewalls specifically.
  • D (default sharing): NSX security groups are not shared automatically - explicit configuration of a redistribution mechanism is always required.

Memory tip: Think of the User-ID agent as a translator and courier - it speaks NSX's language (security groups), translates to firewall language (IP tags), and delivers them to non-NSX firewalls. No courier = no delivery.

Topics

#NSX security groups#Dynamic Address Groups#User-ID agent#VMware integration

Community Discussion

No community discussion yet for this question.

Full PSE-STRATADC Practice