PSE-STRATADC · Question #9
How is traffic directed to a Palo Alto Networks firewall integrated with Cisco ACI?
The correct answer is C. contracts between EPGs that send traffic to the firewall using a shared policy. In Cisco ACI, traffic between endpoint groups (EPGs) is controlled through contracts, and when a firewall is inserted into the path, those contracts are configured to redirect traffic through a service graph - making C correct. The firewall sits as a service node in that graph…
Question
How is traffic directed to a Palo Alto Networks firewall integrated with Cisco ACI?
Options
- Aby creating an access policy
- Bthrough a policy-based redirect (PBR)
- Ccontracts between EPGs that send traffic to the firewall using a shared policy
- Dthrough a virtual machine monitor (VMM) domain
How the community answered
(46 responses)- A4% (2)
- B2% (1)
- C87% (40)
- D7% (3)
Explanation
In Cisco ACI, traffic between endpoint groups (EPGs) is controlled through contracts, and when a firewall is inserted into the path, those contracts are configured to redirect traffic through a service graph - making C correct. The firewall sits as a service node in that graph, and EPG contracts enforce which traffic flows through it.
Why the distractors are wrong:
- A (access policy): Access policies in ACI govern physical/logical connectivity (like port configs), not traffic steering to a firewall.
- B (PBR): PBR is a traditional routing technique used in IOS/NX-OS environments; ACI uses service graphs with contracts for this purpose - not classic PBR.
- D (VMM domain): VMM domains integrate ACI with hypervisors (like VMware vCenter) for virtual endpoint discovery; they don't direct traffic to a firewall.
Memory tip: Think "contracts = traffic rules in ACI." Just as a contract between two parties governs their interaction, an ACI contract between EPGs governs how their traffic flows - including through a firewall service graph. If you see "firewall insertion" + "ACI," think contracts + service graph.
Topics
Community Discussion
No community discussion yet for this question.