City kiosks on a guest VLAN with a walled garden show CB Defense sensors Offline and Intelligent Hub cannot enroll, even though NSX-T identity firewall groups look healthy. What should the security administrator open first?
Select an answer to reveal the explanation.
Short Explanation
A walled garden is a lobby with a locked front door — Hub and the Carbon Black sensor both have to walk out to their SaaS clouds. If the guest VLAN only permits a captive portal, those FQDNs never leave and both products look down even when IDFW groups are perfect. Open the documented outbound destinations first.
Full Explanation
Carbon Black Cloud sensors and Workspace ONE Intelligent Hub require outbound HTTPS to vendor SaaS endpoints. A guest-network walled garden that permits only captive-portal or internal destinations marks sensors Offline and blocks Hub enrollment even when NSX-T identity firewall groups are correctly populated. Identity firewall, Guest Introspection, and NSX Manager do not reach those public FQDNs from off-fabric kiosks. Restore the documented SaaS allow list on the guest VLAN, then recheck sensor and Hub status.