A water-utility operator finds HTTP and SSH mixed on unexpected ports between historian VMs, so TCP/80 alone is not a reliable allow. What should the administrator use in Distributed Firewall?
Select an answer to reveal the explanation.
Short Explanation
Port 80 is a mailbox number, not a promise about what is in the envelope. Context profiles let Distributed Firewall read the application (HTTP versus SSH) even when ports are messy. Hash allow-lists and Access method names do not inspect that flow.
Full Explanation
NSX-T Distributed Firewall context profiles identify application protocols (Layer 7 / APP-ID) independently of the TCP or UDP port. That is the correct control when HTTP and SSH appear on unexpected ports between historian VMs. An L4 service for TCP/80 cannot distinguish those protocols. Carbon Black hash allow-lists and Workspace ONE Access methods are not NSX context profiles.