A city needs east-west isolation between permitting web VMs and tax database VMs that share the same NSX segment. Which firewall should the administrator configure?
Select an answer to reveal the explanation.
Short Explanation
Same-segment VM-to-VM is hallway traffic, not the front door. Distributed Firewall sits on the vNIC and can separate permitting web from the tax database without a north-south hairpin. Gateway firewall and ToR ACLs miss that east-west path.
Full Explanation
NSX-T Distributed Firewall enforces east-west policy at the virtual NIC, including VM-to-VM traffic on the same segment. Gateway firewall on a Tier-0 or Tier-1 is the north-south control and does not see intra-segment east-west that never leaves the host. Physical ToR ACLs are bypassed by overlay east-west. Carbon Black Cloud is endpoint prevention, not the NSX micro-segmentation control for this traffic.