A city administrator creates a Distributed Firewall rule, but it never enforces on hosts. What should be checked first?
Select an answer to reveal the explanation.
Short Explanation
A rule that never realizes is a posted speed-limit sign that never made it to the street. Check realization and that the firewall is actually on for those transport nodes. Access policies and Carbon Black groups will not push DFW to the host.
Full Explanation
NSX-T Distributed Firewall rules must realize on prepared transport nodes with the firewall enabled before they enforce. Realization status and host firewall enablement are the first checks when a created rule has no effect. Workspace ONE Access policies govern administrator SSO, not DFW datapath. Carbon Black sensor groups and managerial control-family comments do not realize NSX rules.