Parks seasonal contractors live in a separate Active Directory forest, and Identity Firewall rules must use those contractor groups. What should the administrator configure?
Select an answer to reveal the explanation.
Short Explanation
IDFW only knows groups from directories NSX Manager can read. A second forest means a second LDAP registration—not a Carbon Black list and not a pile of contractor IPs.
Full Explanation
NSX-T Identity Firewall sources users and groups from directories registered on NSX Manager. A separate contractor forest requires an additional supported LDAP or Active Directory instance so those groups can be used in IDFW rules. Carbon Black watchlists, Access policies, and static IP sets are not IDFW identity sources for that forest.