A water utility wants Identity Firewall user-based rules on Windows VDI but must not enable them on Linux historian hosts. How should IDFW be turned on?
Select an answer to reveal the explanation.
Short Explanation
IDFW is a cluster-or-host switch, not a whole-plant light. Flip it on where the supported Windows VDI lives and leave the Linux historian hosts alone.
Full Explanation
NSX-T Identity Firewall is enabled per cluster or standalone host, and user-to-IP mapping depends on supported guest operating systems. Windows VDI on an enabled cluster can consume AD-group distributed firewall rules; Linux historians on an IDFW-disabled cluster stay out of that identity path. Enabling IDFW fabric-wide, substituting Carbon Black groups, or using Workspace ONE Access does not scope user-based DFW to the supported VDI hosts.