Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks Exam PCSFE Topic 5 Question 17 Discussion

Actual exam question for Palo Alto Networks's PCSFE exam
Question #: 17
Topic #: 5
[All PCSFE Questions]

How must a Palo Alto Networks Next-Generation Firewall (NGFW) be configured in order to secure traffic in a Cisco ACI environment?

Show Suggested Answer Hide Answer
Suggested Answer: B, C

The two requirements for automating service deployment of a VM-Series firewall from an NSX Manager are:

Panorama has been configured to recognize both the NSX Manager and vCenter.

The deployed VM-Series firewall can establish communications with Panorama.

NSX Manager is a software component that provides centralized management and control of the NSX environment, including network virtualization, automation, and security. Service deployment is a process that involves deploying and configuring network services, such as firewalls, load balancers, or routers, on the NSX environment. VM-Series firewall is a virtualized version of the Palo Alto Networks next-generation firewall that can be deployed on various cloud or virtualization platforms, including NSX. Panorama is a centralized management server that provides visibility and control over multiple Palo Alto Networks firewalls and devices. Panorama has been configured to recognize both the NSX Manager and vCenter is a requirement for automating service deployment of a VM-Series firewall from an NSX Manager. vCenter is a software component that provides centralized management and control of the VMware environment, including hypervisors, virtual machines, and other resources. Panorama has been configured to recognize both the NSX Manager and vCenter by adding them as VMware service managers and enabling service insertion for VM-Series firewalls on NSX. This allows Panorama to communicate with the NSX Manager and vCenter, retrieve information about the NSX environment, and deploy and manage VM-Series firewalls as network services on the NSX environment. The deployed VM-Series firewall can establish communications with Panorama is a requirement for automating service deployment of a VM-Series firewall from an NSX Manager. The deployed VM-Series firewall can establish communications with Panorama by registering with Panorama using its serial number or IP address, and receiving configuration updates and policy rules from Panorama. This allows the VM-Series firewall to operate as part of the Panorama management domain, synchronize its settings and status with Panorama, and report its logs and statistics to Panorama. vCenter has been given Palo Alto Networks subscription licenses for VM-Series firewalls and Panorama can establish communications to the public Palo Alto Networks update servers are not requirements for automating service deployment of a VM-Series firewall from an NSX Manager, as those are not related or relevant factors for service deployment automation. Reference: [Palo Alto Networks Certified Software Firewall Engineer (PCSFE)], [Deploy the VM-Series Firewall on VMware NSX-T], [Panorama Overview], [VMware Service Manager], [Register the Firewall with Panorama]


Contribute your Thoughts:

Kristel
8 days ago
Ooh, tricky question. But I reckon C is the way to go - the NGFW needs to be in the loop with the network controller to really lock down that Cisco ACI traffic.
upvoted 0 times
...
Corazon
10 days ago
Haha, a device cluster? That's like trying to herd cats in an ACI environment. I'll go with B, the Layer 3 underlay network.
upvoted 0 times
...
Izetta
11 days ago
I'm not sure about this one. Do we really need to configure the NGFW as a default gateway? That sounds a bit overkill to me.
upvoted 0 times
...
Bernardine
21 days ago
Hmm, I think the correct answer is C. The NGFW needs to receive all forwarding lookups from the network controller to properly secure the Cisco ACI environment.
upvoted 0 times
Ahmed
2 hours ago
No, I believe it should be D. The NGFW must be identified as a default gateway to secure the traffic.
upvoted 0 times
...
Kendra
9 days ago
I think the correct answer is C. The NGFW needs to receive all forwarding lookups from the network controller to properly secure the Cisco ACI environment.
upvoted 0 times
...
...
Andree
21 days ago
But wouldn't it also need to be identified as a default gateway to secure traffic in a Cisco ACI environment?
upvoted 0 times
...
Chauncey
22 days ago
I agree with Rory. Configuring it as a member of a device cluster can provide redundancy and scalability.
upvoted 0 times
...
Rory
24 days ago
I think the Palo Alto Networks NGFW should be deployed as a member of a device cluster.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77