An administrator has configured a security policy with a rule that allows traffic from the 'Trust' zone to the 'Untrust' zone for the application 'web-browsing'. The rule includes a source user group called 'Marketing'. However, users in the Marketing group report that they cannot access the internet. The administrator checks the traffic logs and sees that the sessions are being denied by the implicit deny rule. What is the most likely cause?
If User-ID is not correctly mapping users to the 'Marketing' group, the firewall cannot match the source user in the rule. The traffic will then fall through to the implicit deny rule. Ensuring the User-ID agent is connected and group mapping is configured is essential for user-based rules to function.
Why this answer
User-based rules require User-ID to map IP addresses to users and groups. If the 'Marketing' group is not synchronized, the firewall cannot match the source user, and the session falls through to the implicit deny. Verifying User-ID agent connectivity and group mapping is the first troubleshooting step for user-based policy failures.
Exam trap
The trap here is overlooking User-ID as a dependency for user-based rules and instead blaming application definitions or rule order.