Transit publishes a citizen trip-planner app north-south to the Internet. Where should the administrator place the primary Internet-facing firewall rules?
Select an answer to reveal the explanation.
Short Explanation
Internet-facing traffic is the front door, and the gateway firewall sits in that doorway on the Tier-1 or Tier-0 uplink. Distributed Firewall still matters east-west, but it is not the whole north-south story. Carbon Black on the Edge guest OS is not the NSX gateway.
Full Explanation
NSX-T gateway firewall on the Tier-1 or Tier-0 that owns the uplink is the north-south filter for Internet-published applications. Distributed Firewall on the web VM is east-west at the vNIC and should not be the only control for inbound Internet traffic. Carbon Black Cloud host firewall and Workspace ONE UEM compliance are not the NSX gateway firewall. Place N-S rules on the gateway that owns the citizen-app uplink.