Parks disaster-recovery VMs in a public-cloud region show Carbon Black Cloud sensors Offline. On-premises sensors are fine. The region's cloud security groups allow only management RDP and SSH and never listed CBC SaaS FQDNs. What should the administrator update?
Select an answer to reveal the explanation.
Short Explanation
A cloud security group is just a firewall with a different badge. If it never allows CBC's SaaS, DR sensors starve the same way an on-prem perimeter ACL would. Open those FQDNs on the SG — on-prem DFW and Access ranges will not punch the cloud allow list.
Full Explanation
Carbon Black Cloud sensors in a public-cloud region must egress to CBC SaaS. Cloud security groups, network security groups, and regional firewall allow lists that permit only administrative ports will mark those sensors Offline even when the on-premises org is healthy. On-premises NSX-T gateway firewall, identity firewall, and Workspace ONE Access network ranges do not program those cloud SG rules. Add the documented sensor destinations to the cloud allow lists and recheck sensor check-in.