County Identity Firewall events never update for VDI logons. NSX Manager already has an LDAP connection, but Guest Introspection is missing on the VDI cluster. What should the administrator enable?
Select an answer to reveal the explanation.
Short Explanation
LDAP is the employee roster; Guest Introspection is the badge reader at the door. Without GI on the VDI cluster, Identity Firewall never sees who just logged on. Retrying LDAP will not create that guest logon path.
Full Explanation
Identity Firewall maps users to IPs using guest context. On NSX-T 3.x that path depends on Guest Introspection and supported VMware Tools (or the documented identity logon event path) on the VDI cluster—not on LDAP directory sync alone. Additional LDAP retries refresh group membership but do not capture live logons. Carbon Black Live Response and Workspace ONE Access network ranges do not feed NSX IDFW events.