Parks uses vRealize Automation to stamp NSX-T security tags when a new recreation VM is provisioned. Why does that keep Distributed Firewall true?
Select an answer to reveal the explanation.
Short Explanation
The recreation VM gets its security name badge as it is born. Dynamic groups see the tag and Distributed Firewall is already waiting—no after-the-fact ticket.
Full Explanation
IaaS tools such as vRealize Automation can apply NSX-T security tags at provision time so dynamic group membership and Distributed Firewall policy attach immediately. That is a policy-automation mechanism. Automation does not replace Distributed Firewall, disable Guest Introspection, or substitute guest iptables for NSX policy.