管理者は、Active Directory で定義された特定のユーザーとグループへのトラフィックを許可するセキュリティ ルールをデバイス グループ内に構築する必要があります。Panorama からこれらのルールのユーザーとグループを選択するには、何を構成する必要がありますか? セキュリティ ルールは、デバイス グループ内のファイアウォールを対象とし、グループ マッピングを構成する必要があります。
正解:A
To create Security rules in Panorama that reference specific users and groups from Active Directory (AD), the Panorama-managed firewalls need access to user-to-group mapping information. This is achieved through Group Mapping, which relies on User-ID functionality. In a Panorama-managed environment, a "master device" must be designated within the device group to provide this Group Mapping data. The master device is a firewall that retrieves user and group information from AD (via LDAP or User-ID agent) and shares it with other firewalls in the device group. This ensures consistent user-based policies across all devices in the group.
Option B (User-ID Redistribution) is incorrect because redistribution is used to share IP-to-user mappings, not group mappings, and is typically configured between firewalls or via Panorama's User-ID redistribution feature, not a requirement for selecting users/groups in rules. Option C (User-ID Certificate profile) is unrelated, as it pertains to certificate-based authentication, not AD group mapping. Official documentation specifies that a master device with Group Mapping configured is essential for this scenario.
Reference: Palo Alto Networks Administrator's Guide, PAN-OS 11.2, "User-ID" section - Group Mapping Configuration; Panorama Administrator's Guide, "Device Groups" section.