PSE-STRATADC · Question #47
Which configuration is required to share NSX security groups as tags to be used by Dynamic Address Groups in a non-NSX firewall?
The correct answer is B. a User-ID agent on a Windows domain server. A User-ID agent installed on a Windows server acts as the redistribution bridge between VMware NSX and non-NSX firewalls: it connects to NSX Manager, collects security group membership data, converts that data into IP address tags, and then pushes those tags to the non-NSX…
Question
Which configuration is required to share NSX security groups as tags to be used by Dynamic Address Groups in a non-NSX firewall?
Options
- Anotify device groups within VMware Services Manager
- Ba User-ID agent on a Windows domain server
- CVMware Information Sources
- Dnone, sharing happens by default
How the community answered
(57 responses)- A11% (6)
- B81% (46)
- C5% (3)
- D4% (2)
Explanation
A User-ID agent installed on a Windows server acts as the redistribution bridge between VMware NSX and non-NSX firewalls: it connects to NSX Manager, collects security group membership data, converts that data into IP address tags, and then pushes those tags to the non-NSX firewall so Dynamic Address Groups can reference them. Without this intermediary, the non-NSX firewall has no direct mechanism to receive NSX security group information.
Why the distractors are wrong:
- A (VMware Services Manager): Not a real component in this workflow - this is a fabricated distractor with no defined role in NSX-to-firewall tag sharing.
- C (VMware Information Sources): This is a real Palo Alto feature for pulling general VM inventory directly from vCenter, but it does not handle the redistribution of NSX security group tags to non-NSX firewalls specifically.
- D (default sharing): NSX security groups are not shared automatically - explicit configuration of a redistribution mechanism is always required.
Memory tip: Think of the User-ID agent as a translator and courier - it speaks NSX's language (security groups), translates to firewall language (IP tags), and delivers them to non-NSX firewalls. No courier = no delivery.
Topics
Community Discussion
No community discussion yet for this question.