A library needs one NSX group of Active Directory patrons for Identity Firewall and a separate group of catalog VMs for ordinary distributed firewall rules. How should the groups be defined?
Select an answer to reveal the explanation.
Short Explanation
The group recipe has to match the dish: user-based IDFW wants directory people, while VM DFW wants virtual machines or tags. Mixing the batter the same way for both jobs fails.
Full Explanation
NSX-T groups support multiple criteria—VMs, tags, IP sets, segments, and AD users—but the criteria must fit the rule. Identity Firewall sources are directory identities; ordinary DFW applied-to and typical L4 sources are compute or network objects. A single IP set, a Carbon Black policy group, or Access roles do not satisfy both rule types.