Parks publishes a citizen reservation app. Gateway firewall and Distributed Firewall both have overlapping TCP 443 allows for the same conversation, and hit counts are confusing. How should the administrator document the two planes to avoid double-shadow?
Select an answer to reveal the explanation.
Short Explanation
Two bouncers on the same door will argue about who waved the guest in. Gateway firewall watches the street (north-south); Distributed Firewall watches the rooms inside (east-west). Write that down so overlapping allows stop shadowing each other.
Full Explanation
NSX-T gateway firewall typically enforces north-south traffic to published services, while Distributed Firewall enforces east-west traffic among workloads. Overlapping allows on both planes make hit counts and troubleshooting unreliable unless each plane's ownership is documented and scoped. Any-any on both, treating OSPF as the security control, or disabling DFW on Edges does not manage the dual-firewall overlap.