Public-health clinic VMs resolve names and sync time to shared DNS and NTP servers. In which Distributed Firewall thinking should those flows be classified?
Select an answer to reveal the explanation.
Short Explanation
DNS and NTP are the building’s lights and clocks, not the clinic’s billing app. Put those shared-service flows in Infrastructure thinking so Application default-deny does not break name lookup.
Full Explanation
NSX-T Distributed Firewall categories place Infrastructure above Application. Shared DNS and NTP conversations are infrastructure flows and should be identified and allowed in that category. Treating them as app-specific micro-segmentation, Ethernet MAC-only, or Emergency any-any mis-orders policy and hides operational intent.