ExamGecko
Question list
Search
Search

Related questions











Question 349 - PCNSE discussion

Report
Export

A firewall administrator configures the HIP profiles on the edge firewall where GlobalProtect is enabled, and adds the profiles to security rules. The administrator wants to redistribute the HIP reports to the data center firewalls to apply the same access restrictions using HIP profiles. However, the administrator can only see the HIP match logs on the edge firewall but not on the data center firewall

What are two reasons why the administrator is not seeing HIP match logs on the data center firewall? (Choose two.)

A.
Log Forwarding Profile is configured but not added to security rules in the data center firewall.
Answers
A.
Log Forwarding Profile is configured but not added to security rules in the data center firewall.
B.
HIP profiles are configured but not added to security rules in the data center firewall.
Answers
B.
HIP profiles are configured but not added to security rules in the data center firewall.
C.
User ID is not enabled in the Zone where the users are coming from in the data center firewall.
Answers
C.
User ID is not enabled in the Zone where the users are coming from in the data center firewall.
D.
HIP Match log forwarding is not configured under Log Settings in the device tab.
Answers
D.
HIP Match log forwarding is not configured under Log Settings in the device tab.
Suggested answer: B, C

Explanation:

For HIP match logs to be visible on the data center firewall, the following conditions must be met:

HIP profiles added to security rules: HIP profiles must be applied to security rules on the data center firewall to enforce access restrictions based on the received HIP reports. If the HIP profiles are not associated with the security rules, the firewall will not evaluate traffic against these profiles, and consequently, no HIP match logs will be generated.

User-ID enabled on the incoming zone: User-ID must be enabled on the zone where the users are located in the data center firewall. The User-ID feature is responsible for mapping IP addresses to user names, which is critical for applying policies based on user identity and, by extension, for HIP-based policy enforcement.

The other options (A and D) are related to logging and log forwarding but would not directly impact the generation or visibility of HIP match logs on the data center firewall itself.

asked 23/09/2024
max artusa
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first