A city SOC wants recommended Distributed Firewall allow lists from live east-west overlay flows among permitting VMs. Which tool should the administrator use first to generate those DFW recommendations?
Select an answer to reveal the explanation.
Short Explanation
Think of Intelligence as a traffic camera already sitting on the NSX overlay that can draft the who-talks-to-whom list. vRNI is the bigger physical-plus-virtual map, not the first DFW recommendation engine. Start in Intelligence, then review the suggested allow list in policy.
Full Explanation
NSX Intelligence visualizes overlay flows collected from NSX and produces Distributed Firewall policy recommendations for micro-segmentation. That is the security-operations job for creating a first-pass allow list from live east-west traffic. vRealize Network Insight is the broader underlay-plus-overlay visibility product, not the NSX-native DFW recommendation engine. Workspace ONE Access and Carbon Black Cloud do not generate NSX Distributed Firewall policy from overlay flows.